DEV Community

Josh Waldrep profile picture

Josh Waldrep

Plumber by trade, open-source security by night. Building tools to keep AI agents honest. Creator of Pipelock.

What CSA, SANS, and OWASP Just Told Every CISO About Runtime Agent Security

What CSA, SANS, and OWASP Just Told Every CISO About Runtime Agent Security

2
Comments
4 min read

Want to connect with Josh Waldrep?

Create an account to connect with Josh Waldrep. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Why Domain Allowlists Aren't Enough for AI Agent Security

Why Domain Allowlists Aren't Enough for AI Agent Security

2
Comments
11 min read
The State of MCP Security 2026: Incidents, Attack Patterns, and Defense Coverage

The State of MCP Security 2026: Incidents, Attack Patterns, and Defense Coverage

3
Comments
15 min read
Why AI Guardrails Aren't Enough for Agent Security

Why AI Guardrails Aren't Enough for Agent Security

2
Comments
8 min read
The AI Agent Security Acquisition Wave: What It Means for Buyers

The AI Agent Security Acquisition Wave: What It Means for Buyers

2
Comments
8 min read
MCP Scanner Comparison: Cisco vs Snyk vs Pipelock

MCP Scanner Comparison: Cisco vs Snyk vs Pipelock

3
Comments
7 min read
Best AI Agent Security Tools 2026: 15 Options Compared

Best AI Agent Security Tools 2026: 15 Options Compared

2
Comments
12 min read
Claude Mythos Can Find Zero-Days. What Happens When Your Coding Agent Can Too?

Claude Mythos Can Find Zero-Days. What Happens When Your Coding Agent Can Too?

3
Comments
4 min read
I published my benchmark scores. Your turn.

I published my benchmark scores. Your turn.

1
Comments
4 min read
LinkedIn Scanned 6,222 Browser Extensions. Your AI Agent's Browser Is Next.

LinkedIn Scanned 6,222 Browser Extensions. Your AI Agent's Browser Is Next.

3
Comments
5 min read
What Happens When Your AI Agent Makes an HTTP Request

What Happens When Your AI Agent Makes an HTTP Request

3
Comments
5 min read
One request looks clean. Five requests leak your AWS key.

One request looks clean. Five requests leak your AWS key.

Comments
5 min read
We built a test corpus for AI agent egress security tools

We built a test corpus for AI agent egress security tools

1
Comments 1
3 min read
Guardrails deleted, now what?

Guardrails deleted, now what?

Comments
4 min read
Your MCP server's tool descriptions are an attack surface

Your MCP server's tool descriptions are an attack surface

11
Comments 25
6 min read
"CVE-2026-25253: WebSocket hijacking turns your AI agent into an attack tool"

"CVE-2026-25253: WebSocket hijacking turns your AI agent into an attack tool"

Comments
5 min read
Your AI agent leaks API keys through DNS queries

Your AI agent leaks API keys through DNS queries

Comments
4 min read
Every protocol your agent speaks, scanned

Every protocol your agent speaks, scanned

Comments
4 min read
6 months until the EU AI Act hits. Here's what runtime security means.

6 months until the EU AI Act hits. Here's what runtime security means.

Comments
7 min read
The first AI agent espionage campaign, and what defenses actually matter

The first AI agent espionage campaign, and what defenses actually matter

1
Comments
6 min read
The v0.2 roadmap for Pipelock. GitHub Actions integration, MCP input scanning, smart DLP, and the path to Pipelock Pro.

The v0.2 roadmap for Pipelock. GitHub Actions integration, MCP input scanning, smart DLP, and the path to Pipelock Pro.

Comments
3 min read
Securing Claude Code with Pipelock

Securing Claude Code with Pipelock

5
Comments
4 min read
283 ClawHub Skills Are Leaking Your Secrets. VirusTotal Can't Fix This.

283 ClawHub Skills Are Leaking Your Secrets. VirusTotal Can't Fix This.

Comments
4 min read
Lateral movement in multi-agent LLM systems

Lateral movement in multi-agent LLM systems

1
Comments
5 min read
loading...