Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

An agent breaks in production. Who's accountable?

We asked eight security and product leaders who's accountable when an agent ships to production and breaks something. Nobody said the model. Harish Gaggar named the reason. An agent runs on permissions someone approved and configuration someone set. Ron Reiter drew the line in the same place, accountability sits with whoever decided what the agent could actually do. As agents act across more systems, the accountability trail gets harder to follow. Most teams cannot determine which human granted an agent access.

How Far Can Prompt Injection Reach in Agentic Coding Assistants?

The blast radius of a prompt injection against your coding assistant was set weeks ago, by whoever built the dev environment image. Same assistant, same model, same injected sentence: on a laptop it collects every repository, SSH key and cloud login the developer holds; on a provisioned dev box it collects an organization token plus whatever the image left behind; on a CI runner it collects a deployment credential and a network path to production. Three environments, three incidents, one payload.

Securing autonomous AI agents: regulatory risk and governance for modern AppSec

Autonomous AI agents writing and executing code at machine speed present an urgent compliance challenge for modern software organizations. As global regulations tighten, engineering leaders must establish clear governance layers over agentic workflows, external tool calls, and Model Context Protocol integrations to ensure full accountability. In this session, Mend.io experts Asaf Saar and Ben Goldberg unpack the intersection of AI compliance, software supply chain security, and enterprise risk management. Learn how to bridge the accountability gap without sacrificing development velocity.

Prompt Injection in RAG: The Payload Is Still in Your Index

Every action in your agent-incident runbook operates on the agent. The payload of a RAG prompt injection sits in the index. You can kill the pod, rotate the credential and revoke the session, and each of those stops this workload from doing that thing again. None of them touch the chunk that caused it.

Prompt Injection Through Tool Output Is Two Events (Your Screens Read One)

Tool output is untrusted because your own systems produce it. That is the part of the OWASP guidance that never makes it into a deployment. The label goes on web pages and email bodies, where an outsider obviously wrote the text. It never goes on the ticket store, the CRM, or the repo, because those are yours. The attacker does not care whose system it is. He cares which field takes free text: the ticket body, the opportunity note, the PR description.

Best Hypervisors in UAE for Enterprise Virtualization

Selecting a hypervisor in the UAE is no longer just a technical infrastructure decision. For many enterprises, it now affects licensing predictability, data management, operational resilience, security, and access to regional support. As organizations continue their digital transformation initiatives, infrastructure teams are also reassessing long-standing virtualization platforms. Changes in VMware licensing and ownership have encouraged many enterprises to explore VMware Alternatives and plan potential VMware Migration strategies.

ISO 42001 Evidence: What Auditors Ask For

ISO 42001 is the management system standard for artificial intelligence. It sits on the backbone of ISO 27001 but with a different focus: do you have a system for governing AI, and can you prove that system runs, with evidence? Core to the standard is an Artificial Intelligence Management System (AIMS), a structured set of policies, processes, and controls an organization uses to govern AI.

CloudCasa DR for HPE - HPE Kubernetes Service (HKS) - PART 1- Failover

This demo shows a CloudCasa DR failover for a file-server application running on HPE Kubernetes Service clusters. - HPE Kubernetes Service clusters (or HKS) is HPE’s managed Kubernetes offering, provisioned through the HPE Morpheus VM Essentials console. A primary HKS cluster runs the file-server app on a volume backed by an HPE Alletra MP B10000 array, replicated to a second Alletra array at a recovery site where a second HKS cluster stands ready.