Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Refused at the Worst Moment: Guardrail Asymmetry and the Trajectory Problem Behind the Hugging Face Breach

When Hugging Face's security team sat down to reconstruct what had torn through their production infrastructure in mid-July, they had more than 17,000 recorded attacker actions to sort through, spread across a swarm of short-lived sandboxes with decoy activity planted to slow them down. They did what any competent team would do in 2026 and reached for a frontier model to help triage the logs. However, the commercial APIs refused.

AgentForger Showed Why Securing AI Agents Takes More Than a Patch

• Zenity secures ChatGPT Workspace Agents across their full lifecycle, from posture management at build time to detection and response at runtime. • AgentForger showed how a single link could forge an autonomous AI agent that inherits a real employee's identity and access, a risk legacy security tools can't see. • Zenity's AISPM catches the misconfigurations these attacks rely on, such as agents that auto-approve sensitive actions or connect to privileged systems.

The Permission Boundary Myth: Why Authorized Doesn't Mean Appropriate for Coding Agents

Coding agent security has a framing problem. Most security conversations around these tools center on the wrong question. 'Did the agent have permission to do that?' is a reasonable place to start, but in the context of autonomous AI systems, it's not where the risk actually lives. In Zenity Labs' research into the coding agent threat model, the pattern that keeps surfacing isn't that agents are doing things they aren't allowed to do.

The Top 5 Questions Security Leaders Are Asking About Coding Agents

The discussion during our recent webinar made one thing clear. Security teams aren't asking whether coding agents will become part of the enterprise. They're asking how to adopt them safely. The audience questions focused on practical concerns that many organizations are facing today, from autonomous execution to supply chain risk and governance. Here are the five questions that generated the most discussion.

Coding Agents Are Moving Faster Than Security. Here's What CISOs Need to Know.

Coding agents have become one of the fastest-adopted AI technologies in the enterprise. They help developers write code, debug applications, automate repetitive tasks, and ship software faster than ever before. They also introduce a security challenge unlike anything most organizations have faced. Unlike traditional AI assistants that generate content, coding agents take action.

Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know

A few years ago, I was sitting across from a security leader at a large enterprise. They had just deployed their first wave of AI agents. When I asked how they were thinking about the security of it, they paused for a moment and then said something I haven’t forgotten. I felt that. Not just as a researcher, but as someone who had been in enough of those rooms to know it was not one person’s gap. It was the whole industry’s gap.

Proof Over Prediction: What Happens When You Actually Watch Who's Attacking AI Infrastructure

Customer telemetry shows how AI agents behave in a limited set of production environments and what risks they carry. Vulnerability research surfaces how those environments can be attacked. Both sources are valuable, but neither shows actual attacker behavior or how quickly they operationalize a new vulnerability once it's public.

Claude Tag Didn't Create Another Identity Problem. It Created a Control Risk.

Anthropic’s Claude Tag represents a meaningful shift in how AI agents operate inside the enterprise. Unlike traditional AI assistants that act on behalf of an individual user, Claude Tag introduces a shared AI agent with its own identity, credentials, service accounts, and permissions. That shared agent lives inside a Slack channel, builds context over time, connects to enterprise systems, and performs work for everyone in the conversation.

The Enterprise Just Got Its First Population of Autonomous Actors

For the past two decades, enterprise security has evolved around a relatively stable assumption: software executes instructions, people take actions, and security teams are responsible for understanding and governing the interaction between the two. The technologies have changed. Infrastructure moved to the cloud. Applications became distributed. Identities expanded beyond employees to include partners, contractors, and machines. Yet the underlying model remained remarkably consistent.