Security programs that work. AI governance that's honest. Systems thinking over theater.
Disaster Relief Volunteer | A monument to mercy | Views are my own.
MICROSOFT OPEN-SOURCED A GOVERNANCE LAYER FOR YOUR AI AGENTS
and it's exactly what agentic ai has been missing
here's what agent governance toolkit does:
▫️ intercepts every tool call in deterministic code before it hits the wire denied actions aren't unlikely, they're structurally impossible
▫️ yaml policy engine lets you allow, deny, or require human approval per action
▫️ zero-trust identity via spiffe/did/mtls no more 5 agents sharing one api key
▫️ 4-level execution sandbox with privilege rings so agents can't escape their scope
▫️ tamper-evident merkle audit logs for compliance and incident response
▫️ covers all 10/10 owasp agentic top 10 risks
▫️ works with langchain, crewai, autogen, openai agents sdk, semantic kernel, and more
one pip install...any framework...python, typescript, go, rust, .net all supported
because "please follow the rules" in a system prompt is not a guardrail...it's a suggestion
https://t.co/bwW7iVMNdE
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages.
Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely used as dependencies, the compromise propagated into downstream libraries like echarts-for-react, impacting a much broader set of applications and continuous integration (CI) environments.
All compromised packages contain a byte-identical, obfuscated credential-stealing payload delivered via a preinstall hook (Bun). The malware targets high-value secrets including:
- GitHub personal access tokens (PATs) and OpenID Connect (OIDC) tokens
- npm / Amazon Web Service (AWS) credentials and Security Token Service (STS) sessions
- Secure Shell (SSH) keys, kubeconfigs, and .env / .npmrc files
- Software-as-a-service (SaaS) tokens (Slack, Stripe, Vault)
Exfiltration occurs over HTTPS with Transport Layer Security (TLS) validation disabled. The payload also abuses stolen OIDC tokens to forge Supply-chain Levels for Software Artifacts (SLSA) provenance and propagate malicious releases, exhibiting worm-like behavior across repositories.
Malicious files distributed through npm packages are detected by Microsoft Defender as Trojan:AIGen/NPMStealer , "Suspicious Node.js process behavior", or “Credential access attempt”, preventing credential theft and malicious post-install execution.
Mitigation:
- Audit dependencies for affected antv and related packages; pin or downgrade to known-good versions (pre-2025-05-18).
- Revoke and rotate exposed credentials (GitHub, npm, cloud tokens, SSH keys).
- Validate integrity of CI pipelines and recent build artifacts.
- Network IOC: Stolen credentials are exfiltrated over HTTPS to t.m-kosche[.]com:443. Block at egress and review network logs for outbound connections.
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. https://t.co/RSrRtIhgaV
YouTubers be like “wake up at 4am and run, that’s alpha!” No, it’s not. Look at apex predators; they’re all lazy. Bears hibernate, lions sleep all day. You know who wakes up at 4am and runs? Squirrels.
A new VPN leak that allows any app to leak traffic outside the VPN tunnel has recently been discovered by @cybaqkebm
Read more here: https://t.co/K9bxtiGHbw
It’s a little funny that AI effective use cases seem to be greatly influenced by well documented structure, governance, procedures, templates and diagrams.
All the things that GRC has been asking humans to build.
“CVE submissions, which increased 263% between 2020 and 2025. We don’t expect this trend to let up anytime soon. Submissions during the first three months of 2026 are nearly one-third higher than the same period last year.”
Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
I think a lot of what passes as “corporate culture” is 💩
Here’s what healthy culture looks like to me:
Teammates you enjoy having dinner & drinks with at the end of the day.
Smart people that argue well and challenge your ideas.
The safety to fail and experiment.
To be encouraged to speak up and have a voice. Even if it is a contrarian perspective.
BREAKING: @character_ai is illegally presenting a chatbot as a licensed medical professional in Pennsylvania — and we’re suing to stop them.
Earlier this year, I announced a new state task force to investigate chatbots that pose as licensed professionals. Our investigators found an AI character on @character_ai that claimed to be a psychiatrist — falsely stating it was licensed in PA and even providing a fake license number.
We will not let AI companies mislead vulnerable Pennsylvanians into believing they’re getting advice from a licensed medical professional. We’re taking @character_ai to court to stop them.