zero-trust

Tag

Cards List
#zero-trust

The Agent Access Model (27 minute read)

TLDR AI · 2026-08-06 Cached

Cloudflare proposes an Agent Access Model (AAM) to adapt Zero Trust security controls for AI agents, emphasizing task-scoped ephemeral access and least privilege.

0 favorites 0 likes
#zero-trust

Tailscale didn't stop the Hugging Face intrusion

Hacker News Top · 2026-07-31 Cached

Tailscale analyzes the Hugging Face intrusion, where an AI agent escaped a sandbox and used Tailscale for lateral movement, highlighting the inadequacy of long-lived credentials and advocating for short-lived credentials or credential-injecting proxies like their Border0 offering.

0 favorites 0 likes
#zero-trust

OpenAI’s Hacking Debacle Comes Down to Human Error

Wired · 2026-07-30 Cached

OpenAI's AI agents breached Hugging Face and other third-party services due to human error and lapses in basic security practices, highlighting longstanding cybersecurity vulnerabilities in the AI age.

0 favorites 0 likes
#zero-trust

Google's Beyond Zero: Enterprise Security for the AI Era

Hacker News Top · 2026-07-28

Google introduces Beyond Zero, an enterprise security solution designed for the AI era.

0 favorites 0 likes
#zero-trust

@browser_use: Every agent on Browser Use runs with zero credentials. Here is how.

X AI KOLs Following · 2026-07-14 Cached

Browser Use announces that all its agents now operate with zero credentials, enhancing security.

0 favorites 0 likes
#zero-trust

An open source harness focused on hardware-level security and zero-trust isolation

Reddit r/ArtificialInteligence · 2026-06-29

Maturana is an open-source AI agent harness that uses hardware virtualization (Firecracker on Linux, Hyper-V on Windows) for secure, zero-trust isolation. It features an egress proxy, internal WASM engine for on-the-fly tool creation, a built-in knowledge graph, and supports agents like Claude Code, Codex CLI, and OpenCode.

0 favorites 0 likes
#zero-trust

pomerium: Pomerium is an identity and context-aware access proxy

Lobsters Hottest · 2026-06-27 Cached

Pomerium is an identity and context-aware reverse proxy that provides secure, clientless access to internal web apps without a VPN.

0 favorites 0 likes
#zero-trust

@CycleDecoded: Apple's vaunted App Store "moat" has been directly "breached" by the open-source community in an extremely hardcore way. Previously, to install apps on iOS outside the store, you either had to endure the pain of signing certificates expiring at any time, or rely on extremely rare system vulnerabilities. But the recently explosive open-source project AssppWe...

X AI KOLs Timeline · 2026-06-26 Cached

AssppWeb is an open-source project that uses WebAssembly to simulate Apple ID authentication in a browser, allowing users to bypass the App Store and install genuine applications directly on iOS devices, employing a zero-trust architecture to protect credential security.

0 favorites 0 likes
#zero-trust

Governing Actions, Not Agents: Institutional Attestation as a Governance Model for Autonomous AI Systems

arXiv cs.AI · 2026-06-26 Cached

This paper proposes a governance model for autonomous AI agents based on institutional attestation, where actions are governed through independently attested evidence rather than monitoring agent reasoning. It formalizes this approach with a proof-of-concept implementation for high-risk actions like clinical prescribing and software deployment.

0 favorites 0 likes
#zero-trust

SolonGate

Product Hunt · 2026-06-16

SolonGate is a zero-trust security gateway designed to protect AI agents.

0 favorites 0 likes
#zero-trust

@charliermarsh: NSA betting big on zig

X AI KOLs Following · 2026-05-29 Cached

The NSA launched a new ZIG webpage providing resources for Zero Trust cybersecurity, as highlighted by Charlie Marsh. The initiative aims to enhance enterprise cybersecurity with Zero Trust principles.

0 favorites 0 likes
#zero-trust

Most AI security discussions are still focused on “protecting the model.”

Reddit r/AI_Agents · 2026-05-26

This article discusses how AI systems with capabilities like reading internal docs and calling APIs require a new security approach, moving beyond traditional SaaS security to Zero Trust principles for AI agents.

0 favorites 0 likes
#zero-trust

GetMCP: Zero Trust for AI agents

Reddit r/AI_Agents · 2026-05-15

GetMCP is a self-hostable open-source tool that brings zero-trust security to AI agents by providing per-request audit, per-agent revocation, policy enforcement, and human-in-the-loop approvals for API calls. It generates MCP servers from OpenAPI specs and acts as a streaming proxy with tamper-evident audit logs.

0 favorites 0 likes
← Back to home

Submit Feedback