Loading…
Loading…
Tag
10 posts with this tag.
·9 min read
Copy-paste TypeScript patterns for AI agent output validation: Zod schema enforcement, PII redaction, content policy filtering, JSON repair, hallucination guardrails, and cost circuit breakers. Working code.
·8 min read
Copy-paste TypeScript patterns for AI agent tool authorization: allowlists, scoped tokens, human-in-the-loop gates, rate limits, audit logging, and role-based access. Working code, not theory.
·10 min read
GitHub Copilot and Cursor send your code to external servers. Without governance rules, developers accidentally expose proprietary algorithms, credentials, and customer data. Five rules every engineering team needs before the next PR.
·10 min read
Lumma infostealer via a Roblox script compromised Vercel through a contractor. What this attack chain means for teams on third-party platforms.
·8 min read
The Fed and Treasury convened major banks over AI-driven systemic cyber risk. What it signals for small financial teams and controls regulators expect.
·9 min read
Anthropic's Project Glasswing autonomously found thousands of AI zero-days. Three security posture updates every small team using AI vendor APIs must make now.
·9 min read
AI vendor due diligence in 30 minutes: 5 pass/fail gate questions, 8 deep questions, a 1–3 scoring sheet, and a copy-paste procurement email. No dedicated security team required.
·8 min read
What to do when an AI tool causes a data leak, ships a bad output, or gets misused. A step-by-step response playbook sized for teams without a security team.