← All posts

Platform & Architecture

229 posts on platform & architecture.

Ghostjacking: Tenet Turned Blocked Requests Into Agent Instructions at DEF CON 34

Tenet Security presented Ghostjacking at DEF CON 34 on August 9, 2026. An attacker sends a request designed to be blocked, the firewall logs the payload verbatim, and an AI agent asked to review that log follows the attacker''s text as instruction. In the demonstrated chain the agent rewrote DNS records to point at attacker infrastructure. This piece walks the mechanism step by step and separates the observability fixes from the two controls that live on the AI request path.

llm-securityagentic-aiprompt-injectionai-securitypolicy-enforcementidentity-and-authorization
Read post →

Self-Replicating Prompt Injection Makes Agent Output a Containment Problem

OpenAI disclosed on September 25, 2026 that its GPT-Red red-teaming agent found prompt injections that copy themselves into the next email, file write or code comment. The payload has two goals at once: do the attacker bidding and get reproduced in the output. That shifts the control point from the inbound prompt to the outbound response, which is where an identity-aware HTTP enforcement layer can inspect what an agent is about to publish.

prompt-injectionai-securityagentic-aiai-gatewayincident-response
Read post →

AI Gateway vs LLM Router: The Architectural Distinction That Matters for Enforcement

An LLM router picks the cheapest or fastest model for a given prompt. An AI gateway evaluates whether the request is permitted before any model receives it. The router optimizes cost and latency. The gateway enforces identity-bound policy and produces a per-decision audit record. This piece walks through the architectural distinction, where the two functions overlap, and why an enterprise running regulated workloads needs the gateway capability regardless of whether routing is in scope.

ai-gatewayllm-routerengineeringarchitecturepolicy-enforcement
Read post →

AI Gateway vs API Gateway: What Changes When the Payload Is a Prompt

An API gateway enforces auth, rate limits, and routing on REST and gRPC calls. An AI gateway adds prompt classification, identity-bound policy at the request payload level, and per-decision audit records. The two answer different questions about the same network position. This piece walks through the architectural distinction, the auth model differences, what an API gateway cannot enforce at the prompt layer, and where the two should sit together in production.

ai-gatewayapi-gatewayengineeringarchitecturepolicy-enforcement
Read post →

AI Gateway Performance Benchmark: What to Measure and How

AI gateway performance benchmarks compare proxy products on latency, throughput, and behavior under load. The benchmarks that matter for production deployment are p95 and p99 latency under realistic concurrency, tail-latency behavior when policy evaluation gets expensive, throughput ceiling per node, and behavior under upstream provider degradation. This piece walks through the benchmark methodology that produces production-actionable numbers and the comparison points worth tracking.

ai-gatewayperformancebenchmarklatencyengineering
Read post →

CVE-2026-90898: An AI Gateway That Runs Your Command Before the MCP Handshake

JFrog Security Research reported CVE-2026-90898 in Bifrost, an open-source AI gateway. One unauthenticated POST to the management API registers an MCP stdio client, and the gateway launches the command inside that definition before any MCP handshake runs. The fix is in transports v2.1.0. This walks the registration path, the configuration condition that exposes it, and the control-plane separation the incident argues for.

ai-gatewaymcpvulnerabilitycveai-securityplatform-engineering
Read post →

AutoGen Logging and Tracing: Audit Gaps in Agent Runs

AutoGen logging captures traces, structured events, and OpenTelemetry spans. This guide identifies the fields each path records, explains where debugging telemetry stops, and identifies the identity evidence missing from a model-call audit trail.

agentic-aillm-securityauditforensic-auditai-securityarchitecture
Read post →

GitHub Copilot Audit Logs: What They Record

GitHub Copilot audit logs record enterprise and repository activity. They do not preserve the code context, originating identity, policy decision, and model route for each AI request. This article shows the evidence record a Copilot review needs.

auditforensic-auditllm-securityai-securitydevsecopsidentity-and-authorization
Read post →

Glean Security Review: Trust Center, Access and AI Egress

Use Glean’s Trust Center as the starting point, then test connector access, source permissions, identity propagation, and the model egress decision. A controlled answer request should leave a record that ties the originating user, source reference, model route, policy version and outcome together.

ai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Workday AI Security: Tenant Controls and the Integration Boundary

Workday AI security spans the Workday tenant and business-process permissions, along with identity controls and encryption. It also spans audit evidence and responsible-AI review. Current product pages foreground Sana, Sana AI agents from Workday, and Agent System of Record. Embedded interactions remain inside Workday''s control boundary. A separate HTTP policy layer applies only to customer integrations whose AI traffic is configurable and explicitly routed through it.

ai-securitycloud-securityai-governanceidentity-and-authorizationpolicy-enforcement
Read post →

Slack AI Security: Native Controls and the Custom App Boundary

Slack AI security starts with workspace permissions, Slack AI Guardrails, data protection, and platform administration inside Slack. Custom apps and agents create a separate route when they call external models. Security teams should identify which path each feature uses, test access with named accounts, and apply request policy only to customer-controlled authenticated HTTP LLM traffic.

ai-securityllm-securityidentity-and-authorizationprompt-injectionzero-trust
Read post →

Zendesk AI Security: Separate Data, Access, Logs, and Model Routes

Zendesk AI security spans third-party LLM processing, AI agent workspace roles, conversation records, account-change logs, and actions against connected systems. A production review should test each boundary with its own evidence. Native Zendesk inference stays inside the vendor-managed path, while an independent gateway applies only to a customer-controlled authenticated HTTP model request deliberately routed through it.

ai-securityagentic-aillm-securitypolicy-enforcementidentity-and-authorization
Read post →