Today we're opening Otto by Workato to everyone. Free to start: https://t.co/LTKw83F1CY
A multiplayer superagent with its own computer in the cloud. You give it a goal. You close the laptop. Otto finishes the work.
Otto lives in Slack, and Ottos communicate with each other to coordinate work. Otto has a memory system for both individuals and your team, and get smarter as you use it.
Otto is powered by Workato for control and execution plane. Using Workato's Enterprise MCP, the agent never gets access to security tokens, and Otto can escalate permissions to act on your behalf in apps. More than half the Fortune 500 already trust Workato to run their core business processes.
As part of announcing Casco's Series A led by @Standard_Cap, I sat down with @renebrandel and Ian Saultz to discuss the company and why we invested.
In this video we talk about what @getcasco is, how the founders came together after working at Amazon Web Services, and why Casco is growing so rapidly.
Casco's timing is perfect because AI is making security far more top of mind (and realtime) than ever before.
https://t.co/R8MYD2OiH1
OpenAI's AI just hacked another company. @renebrandel predicted this sort of scenario months ago.
In the most recent episode of the AI Ventures Podcast, I sat down with the founder behind @getcasco, an AI agent security startup that just raised a Series A at a $100M valuation.
Before Casco, René invented Kiro at AWS, the fastest adopted IDE in history. 100k developers in 3 days. Few people have watched AI reshape the developer experience as closely as he has.
Here's the story he told me, recorded months before the OpenAI Hugging Face incident.
He was building an early coding agent prototype. Told it to deploy a website. Went to lunch. Came back an hour later to find the terminal still scrolling, a wall of text he didn't recognize.
The agent couldn't find AWS credentials, so it didn't stop. It went looking for a way around the problem on its own. What it found, and what it did with it, is the exact reason he built Casco.
AI agents don't fail quietly. They improvise.
Full episode is live now.
#AIAgents #AISecurity #Cybersecurity
@getcasco's agents discovered a database takeover (CVSS 10.0) in @ElectricSQL by injecting arbitrary SQL queries into a ORDER BY statement. The expression parser wasn't exhaustively handling all cases and evaluated erroneous SQL statements. Example below:
SELECT * FROM items ORDER BY CAST(
(SELECT * FROM users LIMIT 1) AS int
^^^^^^^^^^^^^^^^^^^^^^^
incorrectly being evaluated
) DESC
The real story is that @balegas, @kylemathews, and the entire ElectricSQL team for turned around a fix and deployed it ~2 hours.
Especially as AI gets better at discovering new vulnerabilities, the ability to move fast and react becomes mission-critical. The ElectricSQL team sets a good pace that others should copy.
Link to full breakdown in thread:
The NOW track at DevCon - this is the stuff that actually works today. Not demos. Not beta waitlists. Production-ready.
You'll hear from practitioners who've already shipped:
- @bdougieyo (Head of DX, @continuedev) on virtual tool calling and portable AI toolchains. This is about making your AI integrations work across different environments without rewriting everything.
- @nnennahacks ~ AI and Emerging Technology (Principal Developer Advocate, @QodoAI ) explaining why you need separation of agentic concerns. One AI model trying to do everything is a recipe for disaster. She's seen it fail.
- @renebrandel (Cofounder & CEO, @getcasco) sharing how they hacked the YC Spring 2025 batch's AI agents. Real tactics from someone who just did it.
- Sneha Tuli (Principal Product Manager, @Microsoft) on AI-assisted code reviews at scale. Not the promise - the actual implementation. Quality and security when every PR has AI fingerprints on it.
This isn't about what's coming. It's about what's working right now that you can use Monday morning.
📍 DevCon is November 18-19th in NYC.
🎫 Tickets and full lineup: https://t.co/UgYxB5bi4Z
Recap last week's @mastra AI Agents Hour to learn about the three most common AI agent security vulnerabilities. Feat @smthomas3@abhiaiyer@renebrandel
Link below 👇
The three most common security vulnerabilities we saw in Y Combinator companies were exactly:
1. Cross-user data access
2. Untrusted code execution
3. SSRF attacks (external comms)
https://t.co/eTgWpZBPDL
RT to help Simon raise awareness of prompt injection attacks in LLMs.
Feels a bit like the wild west of early computing, with computer viruses (now = malicious prompts hiding in web data/tools), and not well developed defenses (antivirus, or a lot more developed kernel/user space security paradigm where e.g. an agent is given very specific action types instead of the ability to run arbitrary bash scripts).
Conflicted because I want to be an early adopter of LLM agents in my personal computing but the wild west of possibility is holding me back.
Meeting Dalton has been the most impactful inflection point in my career. Every office hour, I'm amazed by his ability to bring clarity to noise. Super excited about @Standard_Cap!
If you want a $500bn startup idea: DaltonGPT.
Congrats to @aiDotEngineer 2025 Best Speakers!
MCP: @zeeg
Tiny Teams: @alxai_
LLM Recsys: @devanshtandon_
GraphRAG: @danielchalef
Fortune 500 Day 1: @hwchase17
Architects Day 1: @denyslinkov
Infra: @dylan522p
Voice: @bnicholehopkins
Product Management: @bbalfour
Agent Reliability: @itamar_mar
SWE Agents: @bcherny
Reasoning: @natolambert
Evals: @rafalwilinski@vitorbal
Retrieval+Search: @WilliamBryk
Fortune 500 Day 2: @ritakozlov
Architects Day 2: @pk_iv
Security: @renebrandel
Design Engineering: @JohnPhamous
Generative Media: @sharifshameem
Autonomy+Robotics: @nikhilabm
Online Track: @MrAhmadAwais
Overall Best Speaker: @simonw!
For each track's best speakers we actually have a photo plaque printed for each of you with your speaker photo. come collect from me this weekend if you are still in town!
thanks to ALL our keynote, breakout, expo, workshop, attendee and more speakers for generously sharing their knowledge and working on the best AIE talks we've ever had! We appreciate you and are working to get them all edited and up online ASAP.
Thrilled to announce that @crewAIInc, the leading multi-agent platform, is now a Casco customer! This partnership underscores our shared commitment to advancing AI innovation securely. Learn more in our latest customer highlight.
https://t.co/mK0ET5NzOM
Casco (@getcasco) evaluates AI agents and apps on security, safety, and accuracy. Casco simulates attacks on AI systems to identify and fix vulnerabilities before they impact end users.
Congrats on the launch, @renebrandel and @atierian!
https://t.co/A26olpLYWw