The Board Slide Hiding in Your Agent Telemetry

The measurements that earn an AI agent autonomy are the ones your CFO has been asking for. The quarterly security slide has looked the same for a decade. Vulnerabilities discovered: 14,000. Triaged: 9,200. SLA attainment: 94 percent. Every number on that page describes what the security team did. None of them describes what the business […]

Shrink the Exposure Pile: Vulnerability Management in the Age of Vibe Coding

Part 1 of a two-part series. Security teams already own more scanners, exposure platforms, and dashboards than they can act on, yet the vulnerability backlog grows every week. The bottleneck has moved downstream, from finding vulnerabilities to remediating them, and AI-generated code widens that gap faster than any hiring plan can close it. On a […]

CVE-2025-68664: A Case Study in How AI Agent Velocity Is Stress-Testing Vulnerability Management

The proliferation of AI Agents is creating a “Vulnerability Gold Rush.” While developers are racing to ship features using LangChain, LiteLLM, and the new Claude/OpenAI SDKs, the underlying libraries are evolving so fast that security patches are frequently entangled with massive breaking changes. For an organization running dozens of agents, this isn’t just a maintenance […]

Stop the whack-a-mole game: Turning npm Supply-Chain Chaos into Automated Remediation

In the span of a few weeks, the JavaScript ecosystem has been hit by back-to-back software supply-chain incidents. First came the s1ngularity/Nx compromise in late August. Then, this week, the Shai-Hulud campaign arrived with a twist: a self-replicating, worm-style payload that moved quickly through the npm ecosystem. Public write-ups from SCA and CNAPP vendors have […]