By popular demand, the news brief is now a regular thing. Episode 2: a week in Vegas across Black Hat, DEF CON and Ai4.
Breaking AI agents before the bad guys do. CTO @ ZioSec. Founded ThreatX (acq. A10). 25+ yrs offensive security. Dad, snowboarder, biker. Opinions happen.
- Sanders is quoting the labs' own safety commitments back at them, which is fair. But "pause" only works if everyone pauses, and the people who won't pause don't answer letters from the U.S. Senate. Governance that stops at the border isn't governance.Bernie Sanders has written a letter to Sam Altman, Dario Amodei, and Mark Zuckerberg urging them to immediately pause all AI development in the interest of humanity. And he warns if they do not take appropriate action now, the US Senate will.
- I guess this ecosystem is just never getting fixed.‼️ The popular npm package keyv is being actively compromised (127 million weekly downloads). The attacker is still pushing malware across packages right now. Developing story.
- Start your Claude session from bed, not from your desk. The usage window starts on your first message - you want that clock ahead of you, not behind you.
- Agent Baseline is live from Docker, Snyk and Keycard. 35 controls for enterprise AI agents, open for comment. Validate is outcome five and the one everyone skips. We test whether yours hold. @ZioSecIntroducing Agent Baseline: a vendor-neutral reference architecture for safely building, deploying, and operating AI agents in enterprise environments. Created with @snyksec and @KeycardLabs, this open-source framework sets the minimum standard for agent safety:





