The shift from 2024’s "Chatbots that talk" to 2026’s "Agents that act" is revolutionary. But for security teams, it’s a terrifying leap in the attack surface. In the OWASP community, the most critical conversation right now isn’t about prompt injection;...
Granting AI agents autonomy to access sensitive enterprise systems (MCP) introduces unprecedented security risks. To build trust, a robust framework of AI-specific security guardrails is non-negotiable. Two primary threats stand out: PII Leakage: LLMs can inadvertently expose Personally Identifiable Information...
On January 5, 2026, Google quietly shipped a patch for a high-severity vulnerability in Chrome that most users never heard about. Tracked as CVE-2026-0628 and codenamed Glic Jack, it had been sitting in Google Chrome's Gemini Live integration since September...
In the same week that Google patched CVE-2026-0628 in Chrome's Gemini panel, two separate research disclosures landed that together make a stark case about the state of AI agent security in early 2026. Both involved widely-used AI agent frameworks. Both...
Three AI security incidents. Three different products. Three different vendors. All disclosed within the same two-month window. And all sharing one defining characteristic: the victim did nothing wrong. In each case, there was no phishing email opened, no malicious attachment...
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.