« All posts

AI Agent Security: Six Controls from Nine Incidents

AI agents present three attack surfaces, and six controls can limit potential damage.

AI agents expose three attack surfaces: the host, identity, and the agent itself. Nine incidents from May 2025 to July 2026 affected all three surfaces. Six controls have been identified to limit damage: sandboxing the agent, scoping its credentials, keeping it out of its own configuration, logging every call, scanning the workspace for secrets, and denying by default. These measures help contain the impact of attacks.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work