InfoQ Homepage Security Content on InfoQ
-
From Consumers to Builders: Turning 200 of our Team into Agent Creators in Two Weeks
Ben Maraney explains how Forter enabled R&D teams to build internal AI agents fast by simplifying tools, using custom MCP servers, and removing organizational roadblocks to maximize engineering ROI.
-
Spritely: Infrastructure for the Future of the Internet
Christine Lemmer-Webber and David Thompson discuss Spritely's vision for a decentralized web, explaining capability-based security, actor models, and local-first tech to build resilient apps.
-
APIs for Agents: Rethinking API Programs in the MCP Era
Jim Gough and Andreea Niculcea explain how Morgan Stanley leverages Architecture as Code with CALM and MCP to scale secure, compliant API platforms for AI agents and future protocols like A2A.
-
Fixing the AI Infra Scale Problem by Stuffing 1M Sandboxes in a Single Server
Felipe Huici discusses scaling microVM sandboxes for AI workloads, explaining how millisecond cold boots, high density, and stateful scale-to-zero achieve efficient, secure cloud isolation.
-
Enchant Your AI and APIs with eBPF Magic 🪄
Dan Finneran explains how to use eBPF and AI gateways in Kubernetes to transparently observe, modify, and control unowned AI agent API calls without altering source code.
-
Adopting Memory-Safety and Fine-Grained Compartmentalisation with CHERI
David Chisnall explains how CHERI architecture unifies hardware capabilities and pointer metadata to deliver memory safety and fine-grained, efficient software compartmentalization.
-
Leveraging Adversary Emulation for GenAI Red Teaming
Kennedy Torkura explains how to apply GenAI red teaming to secure AWS Bedrock models and knowledge bases, leveraging MITRE ATLAS to discover cloud supply chain vulnerabilities.
-
Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation
Celine Pypaert explains the shift from reactive firefighting to proactive risk management by identifying vulnerabilities, utilizing SCA tools, and defining ownership within the software supply chain.
-
Are We Ready for the Next Cyber Security Crisis Like Log4shell?
Soroosh Khodami shares a "horror story" on supply chain attacks. He explains how one Maven or npm command can gift hackers a reverse shell and shares critical strategies like SBOMs to defend teams.
-
Security and Architecture: to Betray One is to Destroy Both
Shana Dacres-Lawrence discusses the "betrayals" between security and architecture. She explains how delivery pressure and assumed trust lead to failures and shares five strategies for a lasting union.
-
Panel: Security against Modern Threats
The panelists discuss the challenges in securing the software supply chain against modern threats.
-
Busting AI Myths and Embracing Realities in Privacy & Security
Katharine Jarmul keynotes on common myths around privacy and security in AI and explores what the realities are, covering design patterns that help build more secure, more private AI systems.