Getting Granular with Access, Attributes, and Intent – Alex Olivier – ASW #403
The principle of least privilege access is ubiquitous in recommendations, but perhaps too uncommon in practice. Alex Olivier explains how the AuthZen Working Group has been approaching new standards, guidelines, and practical deployment patterns to make it easier for orgs to establish more refined and correct access policies. It's a problem that predates LLMs, but also one that agents and MCPs made all the more acute. We talk about what intent means when trying to constrain agents' activities, what role LLMs have in policy decisions, and how LLMs can help create a much-needed inventory of access controls.
Segment Resources:
Alex Olivier is co-founder and CPO at Cerbos, an authorization management platform, and co-chair of the OpenID AuthZEN working group, the standard for fine-grained authorization.
With over a decade of experience building and scaling authorization systems at Microsoft, Qubit, Zencargo, and multiple startups, Alex has published extensively on securing Model Context Protocol servers and AI agents. A frequent speaker at events on authorization, AI, security, and identity, including KubeCon, Google Cloud NEXT, Identiverse, and EIC, he combines standards development with practical implementation experience, focusing on the future of authorization for traditional applications, distributed workloads, and emerging AI systems.
Your biggest AppSec problem isn't finding vulnerabilities anymore. It's keeping pace with the code, APIs, AI features, and third-party components shipping into production every day, especially in financial applications where the cost of getting it wrong is measured in fraud, fines, and customer trust.
Join us October 14 for the FinSec Virtual Summit to learn how security and engineering teams are building resilient financial applications without slowing innovation.
Register for free at https://securityweekly.com/finsec using the discount code CSS26-SW
InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Mike Shema
- Updates to Full Disk Access in macOS – Latest News – Apple Developer
In the new world of agents everywhere, granular access control becomes even more important to user choice. But it becomes even more important as choices within a secure by default principle that protects users from overeager access- and data-grabs.
- GLM-5.3 and the spread of advanced cyber capabilities Anthropic
Every story related to model providers has multiple layers. How does this read as anti-competitive? What about running counter to cybersecurity needs? What about an unavoidable trend to open source (more specifically open weights)?
- Hackers Breached Propulsion System of US-Bound Oil Tanker
This is an article that sadly has more supposition and implication than detail, but it goes into the category of biggest IOT device takeover so far.
- Meta Rushed to Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch
- No Time to Pwn: CVE-2026-72018 Linux Kernel LPE | XBOW
John Kinsella
- Rain-related bug caused delay to Malaysia’s Formula 1 race
F1 cars are always bleeding-edge of automotive technology. In the latest "formula," the cars have a hybrid engine setup, mixing gasoline and battery power. Besides managing all the technology, the FIA and Formula 1 have to design checks and balances in the software shared by all the cars to ensure teams cannot find and exploit loopholes.
All this to say, the most recent Malaysia race was to start on a wet track, which meant the cars were going slower on the warm up lap. This led to a series of conditions which uncovered a bug which caused cars to stall on lap. Engineers scrambled and managed to develop a patch to fix the bug in 20 minutes and get the teams to update their cars before the race started.
