The modern enterprise generates and consumes unprecedented volumes of data across operational systems, customer interactions, partner ecosystems, cloud…
Category: DZone Security Zone
A Firewall for AI Agents: Enforce Authority at Every Tool Call
The right firewall for an AI agent goes between the model and every tool that can cause a side effect. Not a prompt filter, an action firewall. An AI…
Why Continuous Application Security Testing Is No Longer Optional
Your last pentest is already out of date. The moment you shipped new code after that report, your risk profile changed, and nobody re-tested it. That’s…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
The Bottleneck of Scaling
Any input/output operation, be it accessing a file, handling an HTTP request, or a database connection, is based on 3 fundamental system concepts — file…
Gossip on Cryptography: Part 3
In this blog, we will continue our discussion from the previous blog, Parts 1 and 2 . If you have not read it, please read it once. So far, we have…
Beyond Agent-Washing: The Engineering Principles Behind Production-Ready AI Agents
An AI agent is not defined by how intelligently it talks. It’s defined by what it’s trusted to do. Give a language model a chat window, and you have an…
Designing a Dynamic Multi-Hierarchy Security Model for Analytics and Decision Support Systems
A simple access check uncovered something alarming: several dashboards still showed employee compensation based on an organizational hierarchy that was no…
Securing Database Connections With Mutual TLS
Stolen credentials served as the entry point in 22% of breaches last year, and in attacks on basic web applications that figure climbs to 88%. Those…
Secure AI Systems: Defending Enterprise Applications Against Agent-Era Threats
The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real…
Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an “embed this” button so they can drop it into a…
Why Your Terraform Drift Alerts Are Useless (And How to Fix Them)
Let me describe a workflow that exists in thousands of engineering organizations right now. Somebody sets up a cron job. It runs terraform plan against…
When Guest Access Becomes an Attack Surface: A Technical Analysis of the City-Forum Campaign
Learn how attackers enumerated Salesforce Experience Cloud and ServiceNow portals — and how defenders can detect and prevent the same abuse. When Guest…
Multi-Account AWS Architecture: Isolating PHI Workloads Without Slowing Down Engineering Teams
Most engineering teams working on healthtech applications reach a point where someone asks a question that sounds simple but isn’t: How do we make sure a…
How to Secure Fintech REST APIs Against BOLA Vulnerabilities
Broken Object Level Authorization (BOLA) occurs when a REST API exposes an object identifier—such as an account, transaction, or loan ID — without…
