『Insecure Agents』のカバーアート

Insecure Agents

Insecure Agents

著者: Allie Howe
無料で聴く

Insecure Agents lives at the intersection of AI engineering and security. Stay ahead of the curve with expert insights, real-world incidents, and bold ideas for safer agents.Allie Howe 政治・政府
エピソード
  • Solving the Agent Identity Crisis, with Sergey Burykin (Uber)
    2026/07/23

    Sergey Burykin, Senior Software Engineer on Uber's AI Security team, joins us to explain the agent identity crisis and how Uber solved it while running roughly 1,000 agents in production.

    Sergey helped write Uber's article "Solving the Identity Crisis for AI Agents," and his core argument is that an agent should be authorized on the intersection of user permissions and agent permissions, never just one. Use only the user's permissions and a hallucinating agent can make calls the user never intended. Use only the agent's identity and any user who reaches the agent inherits access to sensitive business and customer data.

    We get into the infrastructure Uber built to enforce that (a secure token exchange service and an MCP Gateway as the policy enforcement point), why AI security depends on identity, authorization, runtime guardrails, and observability, and why static OAuth scopes break for non-deterministic agents that need dynamic, least-privilege access.

    続きを読む 一部表示
    28 分
  • Security Isn't the Brake, It's the Throttle: Snyk CTO Manoj Nair on Securing Agents at Machine Speed
    2026/07/21

    Manoj Nair, CTO and Chief Innovation Officer at Snyk, joins us at Snyk HQ during AI Engineer World's Fair to discuss the architectural decision he argues the next 24 months of agentic security depend on: the generator cannot be the validator.

    We get into why "the fox guarding the henhouse" is suddenly a live security question ("I can use AI to secure AI, so do I still need a separate security offering?"), why finding vulnerabilities was never the hard part and fixing them safely inside the loop is, and why securing at inception means combining independent models with deterministic data and security research rather than just pointing one model at your codebase.

    Manoj also walks through Snyk's Evo, an agentic security orchestrator built on the fighter-pilot OODA loop that turns a security engineer into a 10X AI security operator, why the agents' own supply chain (the MCP servers and skills they pull at runtime) is now its own attack surface, and why he sees security as the throttle, not the brake.

    続きを読む 一部表示
    27 分
  • The Shared Security Model for AI Agents: Diana Kelley, CISO of Noma
    2026/07/17

    Diana Kelley, CISO at Noma, has spent years on the front lines of enterprise security across IBM, Symantec, and Microsoft, and now she is helping write the rulebook for the agent era. She joins us to make the case that the cloud shared responsibility model does not translate to AI.

    In the cloud there were roughly two responsible parties and your data was always your data. With agents there are at least three, the frontier model provider, the platform or developer building on it, and the user, and the trust boundary has moved from storage to decision-making and action.

    We open on the PocketOS incident, where a coding agent used an over-scoped Railway token to delete a production database and its backups in nine seconds, and use it to trace where responsibility actually lives.

    Diana then walks through AARM, the runtime security specification she co-chairs at the Cloud Security Alliance, why authorization needs five decisions instead of two (allow, deny, modify, step-up, and defer), how much context an agent can actually trust, and why the most useful question a CISO can ask a vendor is not "where does your responsibility end" but "can you sit down and explain how you threat modeled this."

    続きを読む 一部表示
    28 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません