Follow the latest coverage, related explainers and connected technology stories.
Microsoft introduced the Cloud Web Applications Threat Matrix, aligned with MITRE ATT&CK tactics, to organize attack paths spanning application code and deployment pipelines through workload identities and connected cloud services. The framework focuses on helping security teams identify visibility gaps and prioritize hardening and investigation.
Nik Kale argues that securing AI agents should be built as a six-layer chain that begins with inventorying agents and defining their identities and authorization context before reaching policy enforcement through runtime gateways. He proposes a practical framework for testing readiness, with a focus on limited permissions, attributable logs, and a comprehensive shutdown path.