<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Wingback Security blog</title><description>Research and analysis on securing the AI that is actually running in your enterprise.</description><link>https://www.wingback.ai/</link><language>en-us</language><item><title>Agentic Kill Switch: stop the next tool call before it lands</title><link>https://www.wingback.ai/blog/agentic-kill-switch-runtime-emergency-stop/</link><guid isPermaLink="true">https://www.wingback.ai/blog/agentic-kill-switch-runtime-emergency-stop/</guid><description>An Agentic Kill Switch is a runtime emergency stop for AI agents: external to the model, checked before tool execution, and fail-closed when the control plane is unavailable. Here is what security teams should demand, and how public ADR capabilities map to that stop.</description><pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate><category>agent-security</category><category>kill-switch</category><category>agentic-kill-switch</category><category>runtime-defense</category><category>adr</category></item><item><title>You cannot govern AI you have not inventoried</title><link>https://www.wingback.ai/blog/shadow-ai-inventory-before-governance/</link><guid isPermaLink="true">https://www.wingback.ai/blog/shadow-ai-inventory-before-governance/</guid><description>CSA’s Invisible Enterprise research shows most AI tools and agents still run outside IT control. Here is why continuous AI asset inventory is the prerequisite for Agent Detection &amp; Response, and for EU AI Act readiness.</description><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate><category>shadow-ai</category><category>discovery</category><category>ai-governance</category><category>agent-security</category><category>compliance</category></item><item><title>MCP tool poisoning needs runtime controls, not prompt filters</title><link>https://www.wingback.ai/blog/mcp-tool-poisoning-needs-runtime-defense/</link><guid isPermaLink="true">https://www.wingback.ai/blog/mcp-tool-poisoning-needs-runtime-defense/</guid><description>OWASP’s MCP Top 10 and Invariant Labs’ tool-poisoning research show why approving an MCP server once is not enough. Here is what security teams should demand from Agent Detection &amp; Response.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>mcp</category><category>agent-security</category><category>owasp</category><category>runtime-defense</category><category>tool-poisoning</category></item><item><title>Endpoints take the first hit: OWASP Agentic Top 10 for coding agents</title><link>https://www.wingback.ai/blog/coding-agents-inherit-your-credentials-owasp-agentic/</link><guid isPermaLink="true">https://www.wingback.ai/blog/coding-agents-inherit-your-credentials-owasp-agentic/</guid><description>OWASP’s Agentic Top 10 and Microsoft’s 2026 guidance show why ASI02 tool misuse and ASI03 privilege abuse hit developer laptops hardest. Here is what fail-closed Agent Detection &amp; Response looks like for Cursor, Claude Code, and Copilot.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>agent-security</category><category>coding-agents</category><category>owasp</category><category>endpoint-security</category><category>adr</category></item><item><title>CISOs: You Don&apos;t Control the Frontier. You Do Control What It Deploys.</title><link>https://www.wingback.ai/blog/you-dont-control-the-frontier/</link><guid isPermaLink="true">https://www.wingback.ai/blog/you-dont-control-the-frontier/</guid><description>Three takes on pacing the frontier, from Amodei, Beri, and Arora, and why a security program shouldn&apos;t be built around any of them. The job is securing the adoption already happening inside your company.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><category>agent-security</category><category>governance</category><category>ciso</category></item><item><title>Why AI Security Requires a Multi-Layer Platform</title><link>https://www.wingback.ai/blog/ai-security-multi-layer-platform/</link><guid isPermaLink="true">https://www.wingback.ai/blog/ai-security-multi-layer-platform/</guid><description>AI security is not a point problem. Learn why red teaming, runtime protection, shadow AI discovery, observability, and compliance must work together.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>company</category><category>platform</category><category>ai-security</category></item><item><title>Our Baseten connector: cover the models you host, not just the ones you rent</title><link>https://www.wingback.ai/blog/wingback-baseten-connector/</link><guid isPermaLink="true">https://www.wingback.ai/blog/wingback-baseten-connector/</guid><description>Wingback now discovers, guards, and red-teams the models you serve on Baseten (dedicated deployments, Model APIs, and Chains) with the same runtime coverage your frontier APIs get.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>product</category><category>integrations</category><category>announcements</category></item><item><title>Concurrency Is the Capability</title><link>https://www.wingback.ai/blog/concurrency-is-the-capability/</link><guid isPermaLink="true">https://www.wingback.ai/blog/concurrency-is-the-capability/</guid><description>Unit 42&apos;s ten-hour intrusion, OpenAI&apos;s 1,200-agent swarm, and a git config bug. An investigation into what AI-assisted attacks actually changed, and what they did not.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate><category>research</category><category>agent-security</category><category>threat-intel</category></item><item><title>LiteLLM: a security scanner was the initial access vector for AI infrastructure</title><link>https://www.wingback.ai/blog/litellm-supply-chain-compromise/</link><guid isPermaLink="true">https://www.wingback.ai/blog/litellm-supply-chain-compromise/</guid><description>A poisoned vulnerability scanner walked LiteLLM&apos;s PyPI tokens out of CI in March. The 153GB credential archive that surfaced this week shows what an LLM gateway concentrates, and where nobody was watching.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>ai-infrastructure</category><category>incident-response</category></item><item><title>Wingback joins Anthropic&apos;s Cyber Verification Program</title><link>https://www.wingback.ai/blog/anthropic-cyber-verification-program/</link><guid isPermaLink="true">https://www.wingback.ai/blog/anthropic-cyber-verification-program/</guid><description>Verified access to Claude&apos;s high-risk cyber capabilities lets our adaptive red-team engine attack your agents the way a real adversary would, with the guardrails intact.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>company</category><category>red-teaming</category><category>partnerships</category></item><item><title>Why we built Wingback</title><link>https://www.wingback.ai/blog/why-we-built-wingback/</link><guid isPermaLink="true">https://www.wingback.ai/blog/why-we-built-wingback/</guid><description>AI agents now live in three places in your enterprise: on laptops, in your cloud, and inside your own software. Securing one layer isn&apos;t securing AI.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>company</category><category>agent-security</category></item></channel></rss>