Skip to content

Blog

Blog

Insights on AI agent security, product updates, and best practices.

ProductThreat IntelSecurityComplianceEngineering
Product2026-05-27·OpenSyber Team·11 min read

AADR for fintech: defining the runtime security layer for AI agents

AI Agent Detection & Response is the runtime security operations layer agentic AI needs. Why fintech needs it first, how OpenSyber implements it, and what shipped today.

Read more
Product2026-05-23·OpenSyber Team·6 min read

Show HN: PushCI — Catch broken AI-generated code before production

Cursor PRs, Claude-generated migrations, hallucinated infra changes — PushCI catches them before production. Semantic validation, dependency safety, and infrastructure drift detection in a GitHub Action.

Read more
Threat Intel2026-03-28·OpenSyber Team·8 min read

Your AI Code Reviewer Can Be Hacked With a GitHub Issue

Clinejection exposed npm tokens via a poisoned GitHub issue. PromptPwnd hit 5 Fortune 500 companies through Gemini CLI. The fix: validate AI action configs and scan instruction files.

Read more
Security2026-03-28·OpenSyber Team·6 min read

The Supply Chain Attack Hiding in Your Supply Chain Auditor

The Trivy attack spread transitively through setup-trivy. No existing tool scans the full dependency tree of GitHub Actions. SHA pinning the top-level action is not enough.

Read more
Threat Intel2026-03-28·OpenSyber Team·7 min read

AI Agents Are Now Attacking Other AI Agents

An autonomous AI bot powered by Claude Opus spent 10 days scanning GitHub for vulnerable workflows, hitting Microsoft, DataDog, CNCF, and Aqua Security.

Read more
Security2026-03-28·OpenSyber Team·8 min read

The One GitHub Actions Misconfiguration Behind Every Major Supply Chain Attack

Six incidents analyzed: Trivy, tj-actions, Ultralytics, Cline, Checkmarx, ambient-code. The common pattern: pull_request_target running fork code with parent repo secrets.

Read more
Threat Intel2026-03-27·OpenSyber Team·7 min read

The Trivy Attack Was Inevitable

On March 19, 2026, TeamPCP force-pushed a malicious commit to Trivy GitHub Action. 12-hour blast radius, transitive spread, and stolen VS Code tokens. Mutable tags are broken by design.

Read more
Security2026-03-28·OpenSyber Team·6 min read

GitHub Finally Admits Mutable Tags Are Broken

GitHub announced lockfiles, immutable releases, and egress policy for Actions. But it is a roadmap, not shipped. OpenSyber ships SHA pinning today.

Read more
Product2026-03-28·OpenSyber Team·7 min read

Gartner Named Our Category: Guardian Agents

The first-ever Gartner Market Guide for Guardian Agents validates the category. OpenSyber is a pure-play provider with full agent security coverage.

Read more
Security2026-03-21·OpenSyber Team·9 min read

How to Secure AI Coding Agents: The Complete 2026 Guide

To secure AI coding agents, you need 4 things: runtime isolation, credential encryption, behavior monitoring, and supply chain verification.

Read more
Threat Intel2026-03-21·OpenSyber Team·8 min read

The AI Agent Kill Chain: How MCP Server Attacks Work in 7 Stages

The 7-stage attack sequence targeting MCP servers — from AI-powered phishing to credential exfiltration. OpenSyber detects 5 of 7 stages today.

Read more
Threat Intel2026-03-21·OpenSyber Research·7 min read

Slopsquatting: How AI Hallucinated Packages Become npm Attack Vectors

Slopsquatting is an attack where adversaries register npm package names that AI models hallucinate. 4,600 weaponized packages found on npm.

Read more
Compliance2026-03-19·OpenSyber Team·5 min read

EU AI Act Compliance for Agent Platforms

What the EU AI Act means for teams deploying autonomous AI agents in production.

Read more
Engineering2026-03-12·OpenSyber Team·7 min read

MCP Security Best Practices for Production Deployments

How to harden Model Context Protocol servers against prompt injection and data exfiltration.

Read more
Threat Intel2026-03-05·OpenSyber Research·8 min read

Supply Chain Attacks Targeting AI Agents in 2026

From UNC6426 to CursorJack — how threat actors are exploiting the AI agent ecosystem.

Read more
Security2026-02-01·OpenSyber Team·6 min read

Why Self-Hosted AI Agents Are a Security Risk

The hidden dangers of running unmanaged AI coding agents and how to fix them.

Read more
Security2026-03-15·OpenSyber Team·12 min read

The Complete Guide to AI Agent Security in 2026

Everything you need to know about securing AI agents in production — from runtime isolation to supply chain verification.

Read more
Product2026-01-15·OpenSyber Team·4 min read

Introducing OpenSyber: Secure AI Agent Hosting

Why we built OpenSyber and what it means for AI agent security.

Read more