531 posts tagged with "AI agents"
AI agents and autonomous systems

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

Red Hat OpenShift AI Bakes In MCP — and the Bottleneck Moves to Discovery at 10,000 Servers
Red Hat is baking MCP into OpenShift AI as governed infrastructure — Playground validation, a verified catalog, a lifecycle operator, and a gateway. Why the agent tooling gap moved from protocol to discovery at 10,000+ servers, and a six-item checklist for a self-hosted platform's own MCP server.

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.

Render's Agentic Playbook, Read as a Platform Spec: What the Platform Ships vs What Stays Your Code
Render's July 2026 agentic-applications playbook draws an honest line between what a deploy platform ships — queues, retries, per-run history — and what stays in your code: idempotency, compensation, and join policy. This post reads that line as a spec for any Render-compatible API.

What AI Agents Actually Deploy: Vercel's Ship 2026 Numbers and the PaaS Defaults They Break
Vercel's Ship 2026 numbers show agent-triggered deployments passing 50% while AI Gateway tokens grew 10x to 20 trillion a month. What the shift toward inference-calling apps means for PaaS egress, secrets, and metering defaults — and a scorecard for self-hosted platforms.

Zerops's $2M Bet: Your Coding Agent Is the PaaS Customer Now
Zerops raised $2M to build a PaaS control plane for AI coding agents. How its ZCP work loop — live state, deploy evidence, behavior proof — compares to Render and Railway, plus a five-item MCP checklist for self-hosted platforms.

Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access
40% of reachable MCP servers need no authentication and tool-poisoning fools flagship models. A concrete blueprint — scoped credential exchange, an OPA default-deny policy, ephemeral runners — that makes the gateway, not the model, the enforcement point.

Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat
Deploy-from-chat dies the moment the agent asks for your API key. Arcade.dev's MCP runtime — Engine-vaulted OAuth, URL elicitation co-built with Anthropic, per-call scoped credentials — shows how agents deploy without holding tokens, with the deny, revoke, and re-scope paths spelled out.