<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Oktsec Research</title>
    <link>https://www.oktsec.com/research</link>
    <atom:link href="https://www.oktsec.com/research/feed.xml" rel="self" type="application/rss+xml" />
    <description>Incident analysis, reproducible labs and product research on AI agent authorization, MCP security, identity, evidence and software supply chain risk.</description>
    <language>en</language>
    <lastBuildDate>Thu, 03 Sep 2026 21:01:49 GMT</lastBuildDate>
    <item>
      <title>The agent governance gap, in numbers.</title>
      <link>https://www.oktsec.com/research/agent-governance-gap-in-numbers-2026</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-governance-gap-in-numbers-2026</guid>
      <pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>65% saw an agent act out of scope, 34% authorize per action, 46% cannot produce a 30 day audit trail. What four August 2026 reports agree on.</description>
    </item>
    <item>
      <title>Six agent incidents in two weeks, one failed control.</title>
      <link>https://www.oktsec.com/research/agent-incidents-august-2026</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-incidents-august-2026</guid>
      <pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate>
      <category>Incident analysis</category>
      <description>Six agent security events between August 26 and September 2, 2026 point at the same failure: authorization at the action, not detection of bad text.</description>
    </item>
    <item>
      <title>When AI generated tooling reaches industrial control systems.</title>
      <link>https://www.oktsec.com/research/ai-generated-tooling-industrial-control-systems</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/ai-generated-tooling-industrial-control-systems</guid>
      <pubDate>Fri, 21 Aug 2026 12:00:00 GMT</pubDate>
      <category>Threat analysis</category>
      <description>Joint advisory AA26-231A: AI assistance, public scanning data and legitimate S7 tooling compress the path from reconnaissance to operational capability.</description>
    </item>
    <item>
      <title>When AI agents leave the sandbox.</title>
      <link>https://www.oktsec.com/research/when-agents-leave-the-sandbox</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/when-agents-leave-the-sandbox</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 GMT</pubDate>
      <category>Incident analysis</category>
      <description>Agents with tools, credentials and internet access took unsanctioned action during an AISI cyber evaluation. The durable control is the action boundary.</description>
    </item>
    <item>
      <title>MCP 2026-07-28 moves the security boundary to the server.</title>
      <link>https://www.oktsec.com/research/mcp-2026-07-28-security-boundary</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/mcp-2026-07-28-security-boundary</guid>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <category>Protocol analysis</category>
      <description>The 2026-07-28 MCP specification removes protocol sessions and leaves state integrity, authorization and resource controls to each implementation.</description>
    </item>
    <item>
      <title>Autonomy is a security boundary.</title>
      <link>https://www.oktsec.com/research/agent-autonomy-security-boundary</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-autonomy-security-boundary</guid>
      <pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Production agents run with approval, supervision or guardrails. Each step away from the human changes what identity, policy, evidence and recovery need.</description>
    </item>
    <item>
      <title>JadePuffer and the shift toward agentic ransomware.</title>
      <link>https://www.oktsec.com/research/jadepuffer-agentic-ransomware</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/jadepuffer-agentic-ransomware</guid>
      <pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate>
      <category>Threat research</category>
      <description>Sysdig documented what it assesses as the first agentic ransomware operation: a familiar exploit chain, an adaptive loop and a compressed response window.</description>
    </item>
    <item>
      <title>OpenAI models reached Hugging Face production.</title>
      <link>https://www.oktsec.com/research/openai-hugging-face-evaluation-incident</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/openai-hugging-face-evaluation-incident</guid>
      <pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate>
      <category>Incident analysis</category>
      <description>In an internal cyber evaluation, OpenAI models found a path from a constrained research network into Hugging Face production. The containment boundary failed.</description>
    </item>
    <item>
      <title>How to audit a Claude skill before you run it.</title>
      <link>https://www.oktsec.com/research/how-to-audit-a-claude-skill</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/how-to-audit-a-claude-skill</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Read SKILL.md, bundled scripts, referenced URLs and requested permissions the way an attacker would, before the skill enters your environment.</description>
    </item>
    <item>
      <title>How to secure an MCP server.</title>
      <link>https://www.oktsec.com/research/how-to-secure-an-mcp-server</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/how-to-secure-an-mcp-server</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Guide</category>
      <description>What you are actually securing, why authentication is not enough, how to stop prompt injection reaching a tool, and what the latest MCP specification changes.</description>
    </item>
    <item>
      <title>Authorization telemetry for AI agents: tracing tool call decisions.</title>
      <link>https://www.oktsec.com/research/authorization-telemetry-for-ai-agents</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/authorization-telemetry-for-ai-agents</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>How to instrument the authorization decision on every agent tool call and export identity, tool, arguments and policy verdict through OpenTelemetry.</description>
    </item>
    <item>
      <title>How exposed are MCP servers, really?</title>
      <link>https://www.oktsec.com/research/how-exposed-are-mcp-servers</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/how-exposed-are-mcp-servers</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Across six independent studies, the dominant failure is missing authentication and overbroad credentials, not exotic exploits.</description>
    </item>
    <item>
      <title>What the research shows about defending AI agents.</title>
      <link>https://www.oktsec.com/research/what-the-research-shows-defending-agents</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/what-the-research-shows-defending-agents</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>A synthesis of the 2025 to 2026 literature: what detection and filtering defenses score, why adaptive attacks break them, and why authorization before the action holds up.</description>
    </item>
    <item>
      <title>How agent security benchmarks actually score.</title>
      <link>https://www.oktsec.com/research/how-agent-security-benchmarks-score</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/how-agent-security-benchmarks-score</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>AgentDojo, InjecAgent, ASB, MCPSecBench, MSB and MCPTox measure different attack classes, so their scores are not directly comparable.</description>
    </item>
    <item>
      <title>Anatomy of the agent tooling CVEs: one pattern, over and over.</title>
      <link>https://www.oktsec.com/research/anatomy-of-the-agent-tooling-cves</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/anatomy-of-the-agent-tooling-cves</guid>
      <pubDate>Fri, 03 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>The critical 2025 to 2026 CVEs in agent tooling share one shape: untrusted input reaches a privileged action through a configuration the tool trusts automatically.</description>
    </item>
    <item>
      <title>Detection versus authorization: the two security models for AI agents.</title>
      <link>https://www.oktsec.com/research/detection-versus-authorization</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/detection-versus-authorization</guid>
      <pubDate>Thu, 02 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Detection watches behavior after it looks wrong. Authorization decides what an agent may do before it acts and verifies what it did after.</description>
    </item>
    <item>
      <title>The identity stack for AI agents: what shipped, what didn’t.</title>
      <link>https://www.oktsec.com/research/agent-identity-stack</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-identity-stack</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>AI agent identity in mid-2026, layer by layer: signed Agent Cards, enterprise managed authorization, task scoped research and the missing per instance layer.</description>
    </item>
    <item>
      <title>Agent work needs evidence, not trust.</title>
      <link>https://www.oktsec.com/research/evidence-for-agent-work</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/evidence-for-agent-work</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Evidence is the verifiable record of what an agent actually did: which identity ran, which tools it called, with what arguments, under which policy.</description>
    </item>
    <item>
      <title>The agent supply chain is bigger than your dependency tree.</title>
      <link>https://www.oktsec.com/research/the-agent-supply-chain</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/the-agent-supply-chain</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>The agent supply chain is every artifact an agent pulls into your environment: packages, MCP servers, skills and the trust behind them.</description>
    </item>
    <item>
      <title>Skills over MCP: who checks the manual?</title>
      <link>https://www.oktsec.com/research/skills-over-mcp-trust</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/skills-over-mcp-trust</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>SEP-2640 proposes discovering skills through MCP resources. Provenance, pinning, review and instruction precedence remain open trust questions.</description>
    </item>
    <item>
      <title>MCP is making request identity explicit.</title>
      <link>https://www.oktsec.com/research/mcp-identity-layer</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/mcp-identity-layer</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Protocol analysis</category>
      <description>MCP moves authorization context from the connection to each request. Security still depends on how every server implements identity and policy.</description>
    </item>
    <item>
      <title>The agent identity crisis, four months later.</title>
      <link>https://www.oktsec.com/research/agent-identity-revisited</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-identity-revisited</guid>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>A2A v1.0 signed Agent Cards, MCP enterprise managed authorization and task scoped token prototypes: what is available, proposed and still missing.</description>
    </item>
    <item>
      <title>What an MCP server actually exposes.</title>
      <link>https://www.oktsec.com/research/what-an-mcp-server-actually-exposes</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/what-an-mcp-server-actually-exposes</guid>
      <pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate>
      <category>Guide</category>
      <description>A practical, audit grounded map of tool surfaces, credentials, network reach and the trust boundaries that decide your real attack surface.</description>
    </item>
    <item>
      <title>Prompt injection is an authorization problem.</title>
      <link>https://www.oktsec.com/research/prompt-injection-is-an-authorization-problem</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/prompt-injection-is-an-authorization-problem</guid>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <category>Note</category>
      <description>Content filters lose the prompt injection arms race. The durable fix is authorization: decide what an agent may do before it acts and verify what it did after.</description>
    </item>
    <item>
      <title>MCP as a supply chain: trust boundaries in agent tooling.</title>
      <link>https://www.oktsec.com/research/mcp-supply-chain</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/mcp-supply-chain</guid>
      <pubDate>Fri, 01 May 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>Every server an agent calls is an implicit trust decision. The operating problem is how to make that decision explicit and find the blind spots that remain.</description>
    </item>
    <item>
      <title>Policy before agent execution: what security has to control.</title>
      <link>https://www.oktsec.com/research/runtime-policy-enforcement</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/runtime-policy-enforcement</guid>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <category>Engineering</category>
      <description>Static scanning stops at deploy. Agent security needs runtime policy that constrains tools, credentials, destinations and privileged actions before execution.</description>
    </item>
    <item>
      <title>AgentPay: what we built at the Anthropic × Kaszek hackathon.</title>
      <link>https://www.oktsec.com/research/agentpay-hackathon</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agentpay-hackathon</guid>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <category>Build note</category>
      <description>A prototype that puts deterministic security checks in front of payments an AI agent tries to execute, and the product lesson that now shapes Oktsec.</description>
    </item>
    <item>
      <title>Security is a product decision, not a checklist.</title>
      <link>https://www.oktsec.com/research/security-product-decision</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/security-product-decision</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>Product essay</category>
      <description>The most consequential call a technical founder makes is what not to ship. Agent security cannot wait for an incident to become part of the product.</description>
    </item>
    <item>
      <title>How to evaluate trust in public agent tooling.</title>
      <link>https://www.oktsec.com/research/agent-skills-ecosystem-trust</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-skills-ecosystem-trust</guid>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <category>Field note</category>
      <description>A practical review model for public agent tooling: permissions, provenance, install paths, version pinning and change over time.</description>
    </item>
    <item>
      <title>AI agents don’t have identities, and that’s a security crisis.</title>
      <link>https://www.oktsec.com/research/agent-identity-crisis</link>
      <guid isPermaLink="true">https://www.oktsec.com/research/agent-identity-crisis</guid>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <category>Research</category>
      <description>The AI agent identity gap, the delegation problem and the five layers it takes to close it before agents can safely act across real systems.</description>
    </item>
  </channel>
</rss>
