Congratulations to @nickyt.online for giving a successful talk on Agentic Access at Black Hat USA!
Missed the talk? You can come talk to Nick at Booth #6216, right next to Startup City Theater.
#BlackHat #BlackHatUSA #cybersecurity #agenticai #mcp
06.08.2025 19:25 โ ๐ 4 ๐ 0 ๐ฌ 0 ๐ 1
Secure your stack before autonomous AI agents ship code for you | Netlify
Realize the speed, agility and performance of a scalable, composable web architecture with Netlify. Explore the composable web platform now!
On August 12, our CEO Bobby DeSimone will join other security experts to speak about AI agents at Netlify's virtual event.
Working in security, AI/AX, or trying to stay ahead of the curve? This session is for you.
Join the live or sign up to receive the recording afterwards:
ntl.fyi/4mMLR7l
05.08.2025 17:36 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
No AuthZ. No identity checks. No context-aware policy.
The MCP spec is missing core security features, meaning teams deploying MCP-compatible tools are exposing internal APIs without realizing it.
It's time to lock down agent access before it becomes a breach vector.
Read more:
bit.ly/4of50QJ
31.07.2025 16:42 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 1
How Shadow AI Breaks SOC 2 and HIPAAโand What to Do About It
Shadow AI bypasses critical access and audit controls required by SOC 2 and HIPAA. Learn how per-route policy with Pomerium restores visibility, enforcement, and audit readiness.
"74% of organizations have already experienced data leakage through unsanctioned AI use, yet most lack visibility into when or how it happens."
Shadow AI breaks the control systems that SOC 2 and HIPAA rely on.
Identity-aware, per-route policy enforcement can help.
Read more:
bit.ly/4lpG8mR
31.07.2025 16:28 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Shadow AI Risk Playbook: Shadow AI Risk Playbook & Zero-Trust Guide (5-Minute Read) | Pomerium
Shadow AI tools like ChatGPT create hidden data-leak risks. Use this zero-trust playbook to discover, govern, and secure generative AI with Pomerium.
Shadow AI Is Already in Your Organization.
Employees are pasting sensitive code, customer data, and roadmaps into public LLMsโwithout approval, visibility, or guardrails. Blocking ChatGPT at the firewall? That wonโt cut it.
ShadowAI and Why Prompt Filters and Regex Fall Short:
bit.ly/4l6dfLX
29.07.2025 17:38 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Weโre heading to Vegas for Black Hat!
๐ Stop by Booth #6216 for live demos, free swag, and more.
๐ค Make sure to catch @nickyt.online's talk, โAgentic Access: OAuth Gets You In, Zero Trust Keeps You Safeโ
๐๏ธ August 6 at 10:45 AM | Startup City Theater
Come say hi! We're so excited to meet you๐ฅณ
25.07.2025 16:31 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 1
LIVE NOW!
Come hang out with @nickyt.online and @den.dev.
youtube.com/live/U9rSRnj...
23.07.2025 17:13 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Native SSH Access
With v0.30, Pomerium now supports native SSH access.
No agents, no tunnels, no special clients required!
Your SSH connections are:
๐ Zero Trust-aligned
๐ OAuth-backed and centrally authorized
๐ Ephemeral & auditable
๐ Easy to manage at scale
Full Changelog for Native SSH Access:
bit.ly/4lIInCA
22.07.2025 16:43 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Why expose OAuth tokens to every MCP client? @pomerium.io keeps the 'keys to the kingdom' safely locked away while still enabling seamless Google integrations #zerotrust #mcp #security #agenticai
21.07.2025 03:15 โ ๐ 5 ๐ 1 ๐ฌ 1 ๐ 0
Exclusive Hosted Evening: Food, Networking & Raffles with Founders, VCs and Builders ยท Luma
Presented by: GMI Cloud, Pomerium & Singapore Global Network
Date & Time:
๐
Thursday, July 31st
๐ 5:30 PM โ 9:00 PM PT
Location:
๐ Location will be sharedโฆ
@nickyt.online will be speaking about how AI agents need Zero Trust policies that go beyond OAuth's 'what can you do' to answer 'should you be doing this right now' with context-aware, fine-grained controls.
Apply to attend GMI Cloud's AI After Hoursโspots are limited:
lu.ma/dr1t68rs
21.07.2025 16:39 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
And we're live! Come hang as we chat about the 0.30 release with some demos!
16.07.2025 17:03 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0
...And we're live! ๐ฅณ
Join @nickyt.online's livestream as he explores Pomerium v0.30!
www.youtube.com/live/Iz4fBb-...
16.07.2025 17:03 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Explore and deep dive into the features of Pomerium v0.30 with @nickyt.online, Developer Advocate at Pomerium.
Join us TOMORROW, July 16 at 1PM ET!
15.07.2025 16:15 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 2
Nick Taylor and Den Delimarsky's profile pictures and description along with the theme of their livestream "MCP security and authorization"
MCP Security & Authorization
@den.devโฌ, Model Context Protocol (MCP) Steering Committee Member - Security, joins @nickyt.online to discuss MCP security and authorization.
Join us on Wednesday, July 23 at 1PM ET:
www.youtube.com/live/U9rSRnj...
14.07.2025 16:21 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 3
Model Context Protocol (MCP) lets AI agents connect to your tools, but without access control, one prompt can do too much. With @pomerium.io, we set fine-grained policies on servers, all the way down to the tool level. No cooking the books today with zero trust. #mcp #zerotrust #ai
11.07.2025 22:00 โ ๐ 7 ๐ 2 ๐ฌ 0 ๐ 0
Announcing Pomerium v0.30
Just in: Pomerium v0.30!
Pomerium now covers LLM agents, secure SSH, enterprise-grade policy enforcement, and more!
v0.30 features:
๐ก๏ธ ๐ก๐ฎ๐๐ถ๐๐ฒ ๐ฆ๐ฆ๐ ๐๐ฐ๐ฐ๐ฒ๐๐
๐ค ๐๐ด๐ฒ๐ป๐๐ถ๐ฐ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐ฎ๐๐ฒ๐๐ฎ๐
๐ ๐๐ฟ๐ผ๐๐-๐ข๐ฟ๐ถ๐ด๐ถ๐ป ๐๐๐๐ต ๐๐ถ๐
๐ฒ๐
๐ ๐ฆ๐ฐ๐ฎ๐น๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ + ๐ข๐ฏ๐๐ฒ๐ฟ๐๐ฎ๐ฏ๐ถ๐น๐ถ๐๐
๐ ๐ ๐๐น๐๐ถ-๐๐น๐๐๐๐ฒ๐ฟ ๐๐ผ๐ป๐๐ฟ๐ผ๐น ๐ฃ๐น๐ฎ๐ป๐ฒ
Full release:
bit.ly/3IkRPx8
10.07.2025 22:09 โ ๐ 5 ๐ 0 ๐ฌ 0 ๐ 2
When AI Has Root: Lessons from the Supabase MCP Data Leak
A Claude-based IDE with root-level database access was tricked into exfiltrating secretsโjust by reading a support ticket.
No vulnerability. Just a convincing prompt.
Read what went wrong, why Row-Level Security (RLS) failed, and what defenses can actually work.
bit.ly/406KwPE
08.07.2025 16:49 โ ๐ 6 ๐ 2 ๐ฌ 0 ๐ 0
Your Employees Are Already Dumping Company Data to LLMs (Hereโs What To Do About It)
Your team is already sharing sensitive internal data with AI. These AI agents must be bounded by proper guardrails.
Our latest post breaks down:
โข โShadow AI,โ your biggest security blindspot
โข How to build a secure, low-friction LLM gateway
โข Real-world case studies
Read more:
bit.ly/3Ir3N8h
03.07.2025 16:35 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0
Discuss Event-Driven Architecture for AI Agents!
Abhimanyu Selvan, Head of Developer Advocacy (EMEA/APAC) at DigitalOcean, joins @nickyt.online
to discuss event-driven architecture for AI Agents.
Join us on Wednesday, July 16 at 9AM ET:
www.youtube.com/watch?v=-ai4...
02.07.2025 16:33 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 2
June 2025 MCP Content Round-Up: Incidents, Updates, Releases, and more!
Itโs been a busy month in the world of Model Context Protocol (MCP), so weโve compiled June 2025's MCP incidents, industry news, blogs, and other reports for you.
There's a lot to keep up within the space, but it's clear that MCP is here and needs to be secured.
Find it here:
bit.ly/4exZvIz
01.07.2025 17:15 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
5 Key Takeaways about ZTA from NIST SP 1800-35
Zero Trust is all about reducing attack surface, enforcing least privilege, and continuously reevaluating risk.
NIST SP 1800-35 is a a how-to Zero Trust manual based on real technologies, interoperable open standards, and 19 separate implementation builds.
Read key takeaways:
bit.ly/3TfcpBl
30.06.2025 16:16 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Asana's AI Connector Leak Exposed Sensitive Data Across Organizations: What It Means for MCP Security
Stay up to date with Pomerium news and announcements.
Asanaโs MCP bug exposing cross-tenant data serves as a warning that you need guardrails with AI agents.
Things can go wrong when:
โ OAuth is treated as authorization
โ Agent access isnโt scoped or audited
โ No enforcement layer stands between the agent and the system
Read more:
27.06.2025 14:02 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
MCP Security: Zero Trust Access for Agentic AI and Autonomous Agents
Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.
Traditional security models weren't built for autonomous agents.
Our latest MCP guide breaks down:
โ Why MCP changes the security model
โ How Zero Trust protects agent actions in real time
โ What you need to do before connecting LLMs to internal tools
Read the security blueprint:
bit.ly/4687OID
24.06.2025 16:43 โ ๐ 5 ๐ 1 ๐ฌ 0 ๐ 0
The Model Context Protocol Security Reality Check
How to close critical gaps and why proxy-enforced OAuth is essential for secure MCP architectures.
OAuth โ secure by default.
Proxy-enforced OAuth is mandatory, not optional
Read the break down on what the MCP Security Best Practices actually require and where current implementations are falling short on @nickyt.online's latest @thenewstack.io piece:
thenewstack.io/the-model-co...
18.06.2025 17:23 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 1
๐ญ:๐ญ๐ฑ๐ฃ๐ ๐๐ง:
@javasquip.bsky.social, Head of AX Architecture at Netlify discusses AX, MCPs, and using Netlify to ship ideas to production.
www.youtube.com/watch?v=cnPK...
18.06.2025 16:04 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
๐ญ๐ญ๐๐ ๐๐ง:
AI Engineer @tej.as shares about the Langflow project, a new, visual framework for building multi-agent and RAG applications. It is open-source, Python-powered, fully customizable, and LLM and vector store agnostic.
www.youtube.com/watch?v=sIoc...
18.06.2025 16:04 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Tomorrow, we have an incredible guest speaker lineup for our livestreams hosted by @nickyt.online ! Tune in and listen to what @tej.as and @javasquip.bsky.social have to say about building and shipping LLMs and MCPs.
18.06.2025 16:04 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 1
"How do we build these microservice architectures and serverless apps?"
@remotesynthesis.com joined @nickyt.online to discuss LocalStack, an open-core tool that lets developers run a complete AWS cloud environment on their laptop for faster, cost-effective development and testing.
17.06.2025 16:27 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 1