This week's articles
Building an Advanced Agentic Harness
How to build a production-grade agentic harness using typed Pydantic tools, a DAG planner with parallel asyncio execution, tiered memory, Planner/Worker/Critic role separation, multi-dimensional budgeting with graceful degradation, and structured tracing for observability.
Orchestrating AI Code Review at scale
Cloudflare built a CI-native AI code review system using OpenCode, orchestrating up to 7 specialised agents (security, performance, code quality, etc.) per merge request.
A few notes on AWS Nitro Enclaves: KMS integration
This third installment in Trail of Bits' Nitro Enclaves series catalogs passive and active attack classes against enclave-KMS communication, covering CMK substitution, data key swapping, replay attacks, policy misconfigurations, key commitment gaps, and operational risks.
S3 Clones in the Neoclouds
Wiz research examines S3-compatible object storage across neoclouds (Nebius, Vultr, Cloudflare, DigitalOcean, Crusoe, Lambda Labs), covering security risks including public bucket exposure, weak access key patterns, limited least-privilege controls, presigned URLs, encryption gaps, and missing data plane logging.
A security field guide to AI tooling visibility
Monad's security field guide covers logs, blind spots, and detection use cases across 8 AI tools: Claude Code/Cowork OTel, OpenAI Codex OTel, Cursor and GitHub Copilot audit logs, Anthropic Compliance Activity Feed, OpenAI API Platform audit logs, and Google Workspace Gemini activity logs. Each chapter maps what each source records versus what it misses, key fields, and security use cases spanning detection, hunting, IR, and governance.
|