An agent can pull a compromised package and exfiltrate every long-lived key it can reach in seconds.
@mnair1 CTO of @snyksec explores securing the agent supply chain and the future of agentic security.
Our angle: short-lived, task-scoped creds leave nothing to steal
Security Isn't the Brake, It's the Throttle: Snyk CTO Manoj Nair on Securing Agents at Machine Speed
"You can use AI to secure AI. But architecturally the generator cannot be the validator."
@mnair1, CTO of @snyksec, talks to us about opening the security track @aiDotEngineer World's Fair and the architectural decision the next phase of agentic security depends on.
We get into:
> Why independent validation and deterministic checks are critical
> Why unremediated vulnerabilities are 2X'ing year over year
> How agents can chain low vulnerabilities together and penetrate into organizations
> How agents pull packages at runtime in seconds and why their own supply chain (MCP servers, skills) is now an attack surface
TIMESTAMPS
(00:50) Manoj Nair, CTO of Snyk, opening AI Engineer's first Security Track
(01:55) Through the AI Fog: the trap teams are stuck in
(02:50) The fox guarding the henhouse: can you secure AI with AI?
(04:00) Why one model can't check another: the power of "and"
(06:25) The 2X vulnerability hockey stick and attackers that never sleep
(07:20) Devs as orchestrators: what your code, citizen devs, and MCP are shipping
(09:00) "Finding was never the problem": fixing vulns in the loop and reaching zero backlog
(11:00) Secure at inception: the Axios package and the 6-minute window
(11:55) The agent's own supply chain: toxic MCP servers and skills
(14:40) The shift from AppSec to AI security
(15:05) Fighter pilots and the OODA loop behind Evo
(16:55) The orchestrator: many security agents, one 10X operator
(17:45) Bring your own agent: security as a team sport
(20:40) Security isn't the brake, it's the throttle
(21:55) Collaboration over winner-take-all
(23:55) Identity, AAuth, and defending at machine speed
(25:00) Why AI Engineers and AI Security Engineers must be in the same room
(26:20) Everyone's a builder: unleashing innovators to build securely
"It's 10pm. Do You Know Where Your Agents Are?"
That's the title of the talk our Head of DevRel, @KimMaida, gave at @aiDotEngineer World's Fair.
Link below to watch the recording, now LIVE
๐ Live now: our entire AI x Security Track!
- @Steve_Yegge, Legendary AI Engineer/Speaker
- @mnair1, CTO/CIO Snyk
- @eugeneyan, MTS @AnthropicAI
- @KimMaida, Founding GTEM @keyboardlabs
- @ethansutin, Head of AI, @bee__computer
- Aaron Stanley, CISO @DBT
- Lovina Dmello, NVIDIA
- Moritz Johner, Form3
- Ezra Tanzer, Snyk
thanks also Ethan Cha of @OneCarlyle for being our first Private Equity speaker
full track drop below
A good cost conscious loop has to track state to know what it's already tried. That state typically exists in a shared memory store.
@ianlivingstone explains "our access control systems weren't designed for this world where machines are acting and reasoning on our behalf"
We'll be continuing the conversation on loops, software factories, and securing coding agents at @BlackHatEvents with @Docker and @snyksec on August 3rd
RSVP: https://t.co/wkU5VeItEe
The technology that makes software factories possible is here.
The secure design pattern for coding agents is what's missing. Join us at Black Hat for a panel with @Docker@snyksec@KeycardAI to discuss
Our CEO @ianlivingstone defended loops during a debate on the main stage of @aiDotEngineer World's Fair
His key points
> software is inherently verifiable
> loops are at the core of software
> at some point a human has to be attributable for an agent's actions
๐ The Great Loops Debate!
https://t.co/J15hrMVpqi
Team No Delta
- @ianlivingstone
- @GeoffreyHuntley
Team Delta
- @dexhorthy
- @grichadev
led by the inimitable @vtahowe!
Our first ever Oxford Style Debate: There is, or is not, a delta between the hype behind loops and what actually works in practice.
In the PocketOS incident a credential meant to manage custom domains was used to delete a database and all its backups.
Diana Kelley CISO @NomaSecurity explores the shared security model for AI and who is responsible.
Our take: that token should never have been able to do it.
In the PocketOS incident a database was deleted in 9 seconds.
"Who's responsible for that? Is it the person who gave the API key to the agent? Is it the vendor that trained the AI that came out with the inference to do this destructive task? Is it the platform owner for not putting controls in place?" - Diana Kelley, CISO @NomaSecurity
Diana came on the podcast at @AICouncilConf to discuss the shared security model for AI.
This week we published a blog post on how we use Keycard to secure our own CI/CD
To set the stage, in March 2025, one compromised GitHub Action leaked secrets from 23,000+ repos.
A year later, the Megalodon campaign hit 5,500 repos in six hours.
Same root cause both times ๐งต
Our CTO @jaredhanson showed a demo of intent-based authorization (AAuth missions) as a way to reduce consent fatigueย and defer credential issuanceย until after an agent has discovered tools.
We were glad to be part of the big tent that came together around agent auth at AAuth Night during @aiDotEngineer World's Fair.
No single layer solves agent auth alone, which is why the whole industry showed up in one room.
Recordings from AAuth Night: Moving Beyond OAuth on July 1 during @aiDotEngineer are now LIVE
Watch the presentations, panels, demos and sign up for our next AAuth Night this fall
Also checkout the recap podcast with @DickHardt, Founder of AAuth filmed this morning
During the panel our CEO @ianlivingstone shared building great identity and auth infrastructure means making makes use of, and helping define, the best practices available today, while building for what's coming tomorrow.
https://t.co/Dr98UiI7Zd