Tag: security
-
Discounts for VMware and Tanzu software: Under this new agreement, [US] agencies can purchase select Broadcom software solutions at a 64% discount off the list price. These offers are valid until May 2027 across the portfollo” 🔗 New U.S. GSA and Broadcom OneGov Agreement to Help Accelerate Federal Agency AI and Security Initiatives
-
Relative to your interests, Sunday
Is Your AI Assistant Creating a Recursive Security Loop? – AI-assisted coding is starting to eat its own tail: the same LLMs that write code are increasingly asked to review it, explain security decisions, and even override their own warnings. That creates recursive trust loops where “explain your reasoning” becomes an attack surface, and models…
-
Use yours secrets to get generative AI ROI
From an article by my colleagues and me: For generative AI (GenAI) apps to deliver real business value, they need access to your company’s proprietary data. Without it, models default to the public data they were trained on–meaning you get the same generic ideas as your competitors. If everyone is starting with the same new…
-
A whole bunch of security advice for individuals, more plain-spoken than jargon. 🔗 Resources — Stop Hacklore!
-
🤖 AI Security Loops: When Coding Assistants Become Their Own Risk
Developers are embracing AI coding tools to accelerate software creation, but the resulting security landscape is increasingly complex. While AI can detect threats and debug code, relying on it exclusively creates a recursive loop where the same AI that writes code may also incorrectly validate or approve it. Summarized by AI. Source summarized: Shifting Security…
-
🤖 DoD Unveils CSRMC: Automating Continuous Compliance for Cyber Risk at Operational Speed
Summarized by AI. The article explores how defense and enterprise organizations are evolving from traditional, static compliance frameworks toward continuous, automated, and intelligence-driven security models. It traces the U.S. Department of Defense’s (DoD) cybersecurity governance evolution–from DITSCAP in 1997 to the newly announced Cyber Security Risk Management Construct (CSRMC) in 2025–and argues that this shift…
-
Remember when DevSecOps was all the rage?
Enterprises are till trying to figure out DevSecOps: [M]any organizations remain stuck in siloed approaches that pose problems due to competing demands for speed, efficiency and risk reduction. Enterprises that effectively integrate security into software development and deployment–both through platforms and tools, and via cross-team collaboration– are better positioned to drive velocity, quality and innovation…
-
Run your AI stuff in locked down containers and AIs
Good piece on enterprise AI security. The good news, it’s all the same shit. The bad news news, it’s all the same shit. Yes, and: That’s it! The magic sauce is that LLMs are amazingly good at taking this big chunk of text and using their vast training data to produce the most appropriate next…
-
You need a proxy for enterprise AI Google Cloud suggests using a centralized proxy to mediate all communication between clients and remote MCP servers. This proxy enforces access control, audit logging, secret policies, and secure transport, helping reduce the attack surface by having one enforced point rather than many decentralized servers. In addition, Google emphasizes…
-
How to Secure MCP Servers –
-
Strategic Benefits of Private Cloud in Financial Services and Insurance – “Security is the leading driver of workload repatriation from public cloud. 49% cite data privacy and security as the top barrier to GenAI adoption. Organizations are now deploying AI workloads in private clouds nearly as often as public clouds (55% vs. 56%)”
-
Patterns Across 5 Years of YC Investing – There’s always money in the Security Stand.
-
Broadcom’s Tanzu gets AI updates, but is definitely not Kubernetes – Purnima Padmanabhan, GM for Tanzu, explained that these updates can lower the barrier of entry for developers and allow users to more quickly run their applications with AI integration “while maintaining complete security and lower down time… Even though it’s more advanced, it’s actually…
-
A practical guide to coding securely with LLMs –
-
Model Context Protocol has prompt injection security problems – There’s a lot of security work TBD with MCP. // “The curse of prompt injection continues to be that we’ve known about the issue for more than two and a half years and we still don’t have convincing mitigations for handling it.”
-
OpenAI launches ChatGPT Gov for U.S. government agencies – That should get a lot of enterprise CISO’s to move in allowing AI in their orgs. // ”Since the beginning of 2024, OpenAI said that more than 90,000 employees of federal, state and local governments have generated more than 18 million prompts within ChatGPT, using the…
-
OpenAI finally launches screen and live video observation for paying ChatGPT users – CISO’s must be freaking the fuck out about this.
-
To Improve Your Mean Time to Recovery, Start at the Beginning – How to think about securing your cloud native apps, and apps in general.


You must be logged in to post a comment.