Claude API MCP tool-list pinning
Claude API adds MCP tool-list pinning: Review changes before use
Use Claude API MCP tool-list pinning to preserve reviewed definitions, control the first request, and separate schema changes from server authorization.
Claude Code account sync
Claude Code adds account sync: Review what reaches terminals
Review Claude Code account-synced skills and plugins: compare execution behavior, configure managed opt-outs, and verify removal across terminal sessions.
Copilot approvals and human review
Copilot can approve pull requests: Preserve required human review
Configure Copilot pull request approvals without losing required human review. Check counting policy, mixed-file changes, stale approvals, and review evidence.
ChatGPT plugin account boundaries
ChatGPT adds multi-account plugins: Keep actions in the right account
Review ChatGPT multi-account plugin security across credential routing, cached results, write approvals, and source-to-destination data transfers.
Copilot metrics: What stays hidden
GitHub Copilot adds CLI metrics: Reconcile MCP activity with security evidence
Use Copilot's new CLI customization metrics to investigate MCP activity while preserving reporting gaps, hidden names, and the distinction between connections and actions.
Plugin4Shell: Check the checkout
Plugin4Shell disclosed: Check coding-agent plugin sources
Respond to Plugin4Shell by checking actual plugin source hosts, deploying verified agent fixes, and reviewing installed copies separately from update settings.
Claude merges Chat and Cowork
Claude Chat and Cowork merge: Review carried-over permissions
Review retained connectors, folder grants, approval preferences, and cloud tasks after Claude's September 16 Chat–Cowork merger announcement.
Salesforce in Claude: Review access
Salesforce in Claude beta: Review access before rollout
Review Salesforce in Claude's beta plugin, distinguish its setup from custom MCP connections, and verify user permissions, action approvals, and audit evidence.
Codex sandbox escapes
Codex sandbox escapes disclosed: Verify both upgrade paths
Respond to the September 15 Codex sandbox disclosures with separate CLI and desktop upgrade checks, helper inventory, and an evidence-based exposure review.
Claude Managed Agents tool approvals
Claude Managed Agents: Require approval for sensitive tools
Configure Claude Managed Agents tool approvals, separate customer intent from reviewer authority, and recover pending calls without blindly repeating actions.
Claude account restrictions
Claude account restrictions: Close personal access and old connections
Deploy Claude tenant and connector restrictions, review existing OAuth grants, and verify which account and network paths your Enterprise rollout covers.
Agents API sandbox lifecycle
OpenAI Agents API: Manage self-hosted sandbox lifecycles
Connect an Agents API self-hosted sandbox, handle reconnects and uncertain tool outcomes, and clean up session state and provider compute without leaving orphaned work.
Copilot managed permissions
GitHub Copilot managed permissions: Deploy and verify policy
Deploy GitHub Copilot managed permissions, check which users receive them, resolve team and device policy conflicts, and verify approval behavior before rollout.
Copilot audit evidence
Microsoft 365 Copilot: Collect prompts and reconcile audit logs
Collect Microsoft 365 Copilot prompts and responses through Graph, reconcile them with Purview audit records, and track missing evidence without assuming full coverage.
Claude ant apply in CI
Claude ant apply in CI: Preserve state when deployments fail
Use Claude ant apply in CI with reviewed plans, scoped workload identity, serialized updates, and a recovery procedure that preserves partial deployment state.
OWASP LLM Top 10 2026
OWASP LLM Top 10 2026: From Rankings to Runtime Controls
A technical guide to the OWASP LLM Top 10 2026: its evidence-weighted ranking, model-versus-agent boundary, and the controls to verify before release.
OWASP Agent Control Standard
OWASP Agent Control Standard (ACS): What It Controls and What It Doesn't
A technical guide to the OWASP Agent Control Standard: its Guardian boundary, v0.1 schemas, roadmap gaps, failure modes, and an implementation test plan.
Claude Code Enterprise Security
Claude Code Enterprise Security Deployment
Enterprise deployment guide for Claude Code security across managed settings, identity, dev containers, proxy controls, MCP, hooks, OpenTelemetry, CI/CD, and governance.
Control & Observability
Claude Code Control and Observability with OpenTelemetry
Set up Claude Code OpenTelemetry (OTel), lock the collector destination, audit tool and MCP events, and route production telemetry to a SIEM.
Settings, Permissions & Bash
Claude Code Settings, Permissions, and Bash Tool Security
A practical guide to Claude Code settings, permission rules, Bash tool controls, hooks, MCP allowlists, telemetry, and safe defaults for developer teams.
Automated Penetration Testing
Best Automated Penetration Testing Platforms in 2026
A practical 2026 buyer guide to automated penetration testing platforms, autonomous pentesting, automated security validation, CTEM, DAST, BAS, and AI security testing.
AI Security Platforms
Best AI Security Platforms in 2026
Compare AI security platforms by discovery, agent controls, red teaming, runtime protection, and model security, with dated sources and practical buying questions.
Claude Cowork Security Risks
Security Guidance for Claude Cowork and Risks
Claude Cowork can reach local files, browser sessions, plugins, MCP servers, scheduled tasks, connectors, and approved desktop apps. This guide explains the main Claude Cowork risks and the security controls enterprises should put in place before broad rollout.
Claude Code Security Best Practices
Anthropic Claude Code Security Best Practices
Security best practices for Anthropic Claude Code across permissions, Bash, hooks, MCP, sandboxing, proxy controls, telemetry, and CI/CD workflows.
Securing Claude Code
How to Secure Claude Code
A practical enterprise guide to securing Claude Code with permissions, sandboxed Bash, dev containers, managed settings, MCP allowlists, hooks, proxy controls, OpenTelemetry, and CI/CD release gates.
AI Red Teaming Tools
Best AI Red Teaming and Adversarial Testing Tools in 2026
Compare PyRIT, garak, Inspect, DeepTeam, and commercial AI red teaming tools by use case, evidence, and operating cost. Includes a free evaluation worksheet.
Securing Coding Agents
How to Secure Coding Agents
A concise summary of the General Analysis technical whitepaper on securing Claude Code, OpenAI Codex, Cursor, Windsurf, Devin, GitHub Copilot, and Claude Cowork.
Detecting Shadow AI
How to Detect Shadow AI
A practical guide to detecting shadow AI across browser extensions, SWG endpoint agents, network telemetry, SaaS logs, endpoint agents, AI gateways, and MCP gateways.
MCP Server Security
MCP Server Security: A Threat Model for Agent Tool Supply Chains
MCP servers put executable code, tool schemas, credentials, and agent context in one path. This primary-source threat model covers nine attack classes, current CVEs, and the controls that contain them.
Claude Cowork vs Claude Code
Claude Cowork vs Claude Code: Security Differences for Enterprise
Claude Cowork and Claude Code share an agentic architecture but ship very different enterprise controls. A primary-source comparison of sandbox, network, audit-log, MCP, and decision-framework differences for security teams.
Claude Compliance API
How to Audit Claude with the Compliance API
Anthropic's Compliance API exposes activity events, Claude.ai content, organization settings, and supported Cowork and Claude Code session transcripts. This guide explains current coverage, setup, retention, exclusions, and the controls that still need a separate enforcement layer.
Securing Claude Cowork
How to Secure Claude Cowork
Claude Cowork brings Claude Code-style agentic work to local files, browsers, apps, plugins, and scheduled tasks. Here is how to put a middleman proxy, browser controls, computer-use limits, and enterprise monitoring around it before using it on real work.
What Is AI Red Teaming?
What Is AI Red Teaming? A Practitioner's Guide
AI red teaming is adversarial testing of AI systems to find exploitable vulnerabilities before attackers do. Learn how it works, key techniques, real exploit examples, and how to implement it.
What Are AI Guardrails?
What Are AI Guardrails?
A complete guide to AI guardrails: what they are, the eight main types, how they work architecturally, and how to evaluate them for production LLM and agentic deployments.
OWASP Agentic AI Top 10
OWASP Top 10 for Agentic AI: What Matters Most?
An analytical guide to the OWASP Top 10 for Agentic Applications 2026: what the ten risks are, how they relate to each other, and what they imply for builders of agentic systems.
AI Guardrails
Best AI Guardrails in 2026: Tools, Architecture, and How to Choose
Compare AI guardrails by control type, deployment, and limitations. Learn how to measure false positives, latency, and policy coverage before choosing a tool.