Applying Zero Trust Principles to Agents – Kieran Human – ASW #397
Kieran Human is the Lead Cybersecurity Engineer at ThreatLocker, known for his technical depth and public speaking on cyber risks. He earned a Bachelor’s degree in Information Technology with a minor in Secure Computing and Networks, followed by a Master of Science in Cybersecurity and Privacy from the University of Central Florida. His graduate thesis explored the intersection of cryptocurrency and cybercrime.
At ThreatLocker, Kieran’s work spans cyber threat analysis, technical communications, product development, and investigating advanced technical issues for enterprise clients. He also contributes to internal research and product refinement, working with developers to address security concerns.
Kieran is a frequent author of white papers and produces ThreatLocker educational webinars in collaboration with CEO Danny Jenkins. He approaches every technical challenge as a puzzle to be solved, aiming to deliver clear, actionable solutions while fostering a deeper understanding of cybersecurity.
- Threat intelligence should help you decide what to fix, but most of the time it’s disconnected from your code, your pipelines, and your actual risk.So how do you make it relevant to AppSec?At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, learn how to apply intel to vulnerability prioritization and focus on what’s truly exploitable.Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW
- Unlock the full InfoSec World experience with the All Access Pass, featuring premium workshops, exclusive content, VIP experiences, and expanded opportunities to connect with cybersecurity leaders across industries. Join us in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Mike Shema
- A revisit of remote Spectre attacks on Cloudflare Workers
A nice example of updating a threat model, re-evaluating defenses, and maintaining systems.
- OWASP Agentic Skills Top 10
Time for a new list. It even has a section called “Why It’s Unique to Skills”. Although it seems more fitting to say, "How It Applies to Skills".
- Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilities – Decipher
- Red Agent Exploits Snowflake Vuln Missed by Github Copilot | Wiz Blog
When a code change shouldn't have changed code because the original pattern was the secure pattern and the flaw that was introduced could have been identified with a simple pattern match.
- [LOL] Felony Bench
We have benchmarks for everything now.
John Kinsella
- Anthropic limits direct access to Mythos
Anthropic seems to be limiting direct access to it's Mytos-class models by working with ISVs and allowing them to create and execute prompts on their users behalf. The idea here is to minimize the chance of an end user getting Mythos to generate exploits
