In this blog, we will continue our discussion from the previous parts. If you have not read them, please read them first. Parts 1 & 2 – Caesar Cipher,…
Tag: DZone Security Zone
Are Passphrases Still Secure in the Age of AI?
The short answer up front: Yes, but only if the passphrase is genuinely random . Passphrases emerged as a direct response to a well-known problem with…
Your Cloud Diagram Is Already Out of Date: An Operating Model for Continuous Security Architecture
The Diagram-to-Deployment Gap Cloud security architecture often begins with a strong design, account boundaries are defined, identity federation and…
The Silent Container Death: A TCP Dial That Never Times Out
A pod goes into CrashLoopBackOff . You pull the logs expecting a stack trace, a panic, an error string – anything that points you somewhere. Instead, you…
Detection and Response Did Its Job. Now Someone Has to Actually Fix It.
A host is isolated. A malicious process is killed. A compromised credential is revoked before an attacker can use it again. Detection and response worked…
Locking Down the Enterprise: Data Security Patterns for AI Integrations
Every enterprise conversation about artificial intelligence eventually arrives at the same uncomfortable question: what happens to our data once it leaves…
Building a Secure MCP Server for File Processing: Auth, Rate Limiting, and Idempotency
Most write-ups on building an MCP server focus on the protocol itself: defining tools, handling requests, wiring up a client. That part is genuinely…
How to Build a Production-Ready iOS App With AI-Generated Code
Vibe coding has compressed the distance between an idea and a runnable application. Natural-language instructions can now produce SwiftUI screens,…
Your Application Has an Unindexed Attack Surface. Do You Know What’s in It?
Security teams usually describe an application through the assets they know about. This includes the production domain, documented APIs, the services…
Data Governance for the Agentic Era
The modern enterprise generates and consumes unprecedented volumes of data across operational systems, customer interactions, partner ecosystems, cloud…
A Firewall for AI Agents: Enforce Authority at Every Tool Call
The right firewall for an AI agent goes between the model and every tool that can cause a side effect. Not a prompt filter, an action firewall. An AI…
Why Continuous Application Security Testing Is No Longer Optional
Your last pentest is already out of date. The moment you shipped new code after that report, your risk profile changed, and nobody re-tested it. That’s…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
The Bottleneck of Scaling
Any input/output operation, be it accessing a file, handling an HTTP request, or a database connection, is based on 3 fundamental system concepts — file…
Gossip on Cryptography: Part 3
In this blog, we will continue our discussion from the previous blog, Parts 1 and 2 . If you have not read it, please read it once. So far, we have…
