Kaamos

Blog

What AI changes about cybersecurity. Recent news, explained through the decisions your team needs to make.

All postsNewest first
  1. 012 min

    Prompt injection

    Invisible text, visible risk: what ASCII smuggling means for AI security

    Microsoft’s September research connects invisible Unicode text with phishing evasion. What engineering teams should check in email and AI workflows.

  2. 022 min

    Application security

    AI makes bot attacks cheaper. Measure what they cost your business.

    Cloudflare’s Adaptive Intelligence announcement puts bot economics in focus. A practical way to evaluate abuse defenses without blocking real customers.

  3. 032 min

    Agent security

    An AI sandbox needs proof, not a reassuring name

    Anthropic’s August security update shows why agent sandboxes need tested boundaries, independent monitoring and a reliable stop mechanism.

  4. 042 min

    Software supply chain

    A popular AI agent is still a software dependency

    GitHub’s OpenClaw maintainer interview highlights the security work behind a fast-growing AI project. What teams should verify before adoption.

  5. 052 min

    Vulnerability management

    AI can find more vulnerabilities. Who is going to close them?

    Anthropic’s disclosure dashboard shows the work between finding a vulnerability and getting it patched. How teams can build a useful triage process.

  6. 062 min

    Vulnerability management

    The patch is coming. What protects the service until then?

    Microsoft’s August patching analysis highlights the gap before remediation. How to track temporary controls, patch ownership and verified recovery.

  7. 072 min

    Agent security

    An MCP connection is a permission decision

    Cloudflare’s August MCP security update highlights the controls around agent tools. A practical review of identity, server permissions and audit records.

  8. 082 min

    Defensive AI

    More capable cyber AI still needs a scoped job

    OpenAI’s August Daybreak expansion raises practical questions about authorized scope, security evaluation and evidence quality for defensive AI workflows.

  9. 092 min

    AI data security

    Your AI gateway is also a data system

    Cloudflare’s AI Gateway update makes request visibility easier. What teams should decide about prompt retention, access and provider routing.

  10. 102 min

    Agent governance

    Give AI agents an identity you can review

    Microsoft’s August Zero Trust update brings AI and DevSecOps into the same review. How to connect agent identity, code changes and deployment evidence.