A simple access check uncovered something alarming: several dashboards still showed employee compensation based on an organizational hierarchy that was no…
Category: DZone Security Zone
Securing Database Connections With Mutual TLS
Stolen credentials served as the entry point in 22% of breaches last year, and in attacks on basic web applications that figure climbs to 88%. Those…
Secure AI Systems: Defending Enterprise Applications Against Agent-Era Threats
The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real…
Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an “embed this” button so they can drop it into a…
Why Your Terraform Drift Alerts Are Useless (And How to Fix Them)
Let me describe a workflow that exists in thousands of engineering organizations right now. Somebody sets up a cron job. It runs terraform plan against…
When Guest Access Becomes an Attack Surface: A Technical Analysis of the City-Forum Campaign
Learn how attackers enumerated Salesforce Experience Cloud and ServiceNow portals — and how defenders can detect and prevent the same abuse. When Guest…
Multi-Account AWS Architecture: Isolating PHI Workloads Without Slowing Down Engineering Teams
Most engineering teams working on healthtech applications reach a point where someone asks a question that sounds simple but isn’t: How do we make sure a…
How to Secure Fintech REST APIs Against BOLA Vulnerabilities
Broken Object Level Authorization (BOLA) occurs when a REST API exposes an object identifier—such as an account, transaction, or loan ID — without…
Why DAST Findings Are Hard to Fix and How to Make Them Actionable
Dynamic testing is essential because it uncovers vulnerabilities in running applications. But while SAST gets the attention because it’s shift-left and…
Future-Proofing JWT Security: Crypto-Agility, Post-Quantum Signatures, and IAM Migration
Today, applications are built around identity systems. All API gateways, microservices, mobile backends, and single sign-on flows require some form of…
5 Infrastructure Controls for Securing AI Agents
The Disturbing Discovery In July 2026, the AI Red Team at NVIDIA published findings of a six-month assessment review of enterprise AI agents, ranging from…
The AI Memory Security Blueprint
Designing Context Isolation, Retrieval Trust, and Vector Database Governance for Enterprise RAG Systems Part 1 — Five Documents Can Hijack a Frontier…
The Agent in Your Pipeline Doesn’t Have a Manager. That’s the Problem.
AI coding tools made developers faster. Nobody asked what happened when the tools started making decisions. I want to start with a question that most…
Uncover Security Risks in Your Agent Skills Before Deploying
This tutorial explains how to catch a dangerous agent skill before an agent ever runs it: review it automatically, block it in CI if it fails, and only…
We Empowered AI Agents With ‘Hands,’ Now We Require Kernel-Level Vision to Monitor Them
The cybersecurity industry has been looking at large language models (LLMs) for the past few years as a scary librarian who can be slightly dangerous. We…
Why AWS and Azure Handle Data Perimeter Differently
AWS can send audit logs to an attacker’s account unless denials are enforced at the network layer, while Azure doesn’t log network-block requests at all.…
The AI Memory Security Blueprint
Designing Context Isolation, Retrieval Trust, and Vector Database Governance for Enterprise RAG Systems Part 1 — Five Documents Can Hijack a Frontier…
The Agent in Your Pipeline Doesn’t Have a Manager. That’s the Problem.
AI coding tools made developers faster. Nobody asked what happened when the tools started making decisions. I want to start with a question that most…
Uncover Security Risks in Your Agent Skills Before Deploying
This tutorial explains how to catch a dangerous agent skill before an agent ever runs it: review it automatically, block it in CI if it fails, and only…
We Empowered AI Agents With ‘Hands,’ Now We Require Kernel-Level Vision to Monitor Them
The cybersecurity industry has been looking at large language models (LLMs) for the past few years as a scary librarian who can be slightly dangerous. We…