Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Approved Tools, Unapproved Agents

Approval works at the tool layer and it works well. A platform is assessed, terms are reviewed, a data processing agreement is signed, the tool enters the register, and named identities are entitled to it. Everything about that maps cleanly. ‍ Then somebody uses the approved platform to assemble an agent that acts on their behalf, with its own reach and its own credentials. The approval covered the application.

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning

In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security.

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. Cloudflare plans to achieve full post-quantum security by 2029. Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC.

WebInject: The Web Agent Prompt Injection With No Payload

A browser agent in your cluster opens a supplier portal, screenshots it, and clicks somewhere the task never called for. The page looks exactly like the page the supplier serves, and to the person who checks it later, it still does. The classifier in front of the agent returned nothing, because the instruction that produced the click does not exist.

Is prevention essentially a solved problem?

Stopping new security issues in agent-generated code from being deployed is, architecturally, a solved problem. Prevention is the act of keeping a new vulnerability in code from reaching production at any point in the development and release process, including but not limited to preventing its introduction in a feature branch.

Looking Ahead from VMware Explore

Our time at VMware Explore reinforced what we believe and continue to see across the industry: VMware remains the leader in virtualization and cloud infrastructure. VMware Cloud Foundation (VCF) continues to push the envelope with a powerful set of built-in capabilities that help organizations build, operate, and secure modern environments. Time and again, we saw how these capabilities are enabling businesses to simplify complexity and operate with greater confidence.

Gamepad Mapper vs Controller Remapper: What's the Difference?

PC gamers often come across terms such as gamepad mapper, controller remapper, and controller mapping software. These terms can sound interchangeable, and in many cases they are used to describe similar tools. However, there are some differences in how these applications are typically used. Understanding the terminology can help you choose the right solution for your setup. Whether you simply want to change a few buttons or build a completely customized control scheme, the important thing is to understand what the software can actually do.

How Wearable Technology Turns Everyday Movement into Meaningful Data

A walk to the shops rarely feels worth recording. Neither does climbing stairs with laundry or taking a longer route home. Yet these ordinary movements make up part of daily activity. Wearable technology gives those scattered moments a visible record, creating an opportunity to notice routines that memory alone might overlook.