Our Head of Product Marketing @KasiaatBI moved into the engineering Gitlab repo. Not to learn Git but to compress distance between product context and marketing distribution 🧵
Pushing it one step further, she built a sign up > HubSpot > enrichment > dashboard automation pipeline.
No engineering ticket. No backlog. A marketer, working in a repo, shipping ops infrastructure. 🤯
It turns out a lot of marketing is repetitive tasks fitted to different contexts. So she built Skills in Claude Code that enforce brand voice, kill AI slop, and pull directly from product specs.
Output: nurture sequences, sales outreach, one pagers, ad copy. All grounded in facts of what actually shipped.
Your AI agent will do whatever it's told.
Not just by you.
Every tool result is a potential prompt injection and it doesn't have to happen all at once.
Jasson Casey from @beyondidentity calls it the Ron Burgundy problem.
Who's checking yours?
#cloudsecurity#AIsecurity
Step 1: build an agent to manage the deluge of security alerts
Step 2: give said agent credentials and access to do its tasks
Step 3: HOLY SH*T FIGURE OUT HOW TO GOVERN SAID AGENT
Or our security engineer’s adventures building with @claudeai and securing the autonomous agent
Sanctioning an AI tool ≠ governing it.
A developer runs the Claude Code you approved, but logged in with a personal account. This means your managed config doesn't apply and your audit trail sees nothing.
The agent is sanctioned. The session is not.
Three gaps most security teams miss, and how to close them: https://t.co/JD4mPkuWo7
Every new AI agent your team ships = another API key living somewhere you don't fully control.
Nobody's doing anything wrong. That's just how credential checkout works at scale.
The problem compounds quietly until it doesn't. We wrote about what the architecture looks like when you stop distributing secrets to endpoints entirely, check it out:
https://t.co/z68mi3ihJf
Your devs are using AI agents. Do you know whose API keys they're using? Or if their device is secure?
Ceros is an agentic AI trust layer that gives you visibility and control.
- Bind sessions to verified identities
- Enforce device posture
- Vault API keys in hardware
- Control tool & MCP server access
Public preview is now open. Read the announcement: https://t.co/RwKe04pepc
AI has made research 10x faster but the new bottleneck is coordination costs and sharing insights.
We're trying GitHub-first at @beyondidentity: pull what the team contributed overnight, ask Claude "what changed that I should know?" What are other teams trying?
IT teams spend 40% of their time on account lockouts. It's not just costly, it’s avoidable. Not only is Beyond Identity passwordless (no more password resets!) we're also keeping customers ahead of the game with a new self remediation feature: https://t.co/r8G1Eatjlx
Google Threat Intelligence Group details the ways threat actors are misusing AI tools, including how they are generating and executing AI-enabled malware.
🔗 Read this latest report on our blog: https://t.co/VfvwpLFQXn
If you feel like you're bad at your job and it's making you depressed, just consider that, as the investigation of the recent heist revealed, the password to access the Louvre's videosurveillance system was "Louvre".