OXYNE PLATFORMAgentic Security
Blog

Product updates and engineering notes.

What we're shipping on the Oxyne platform, and why.

Latest blog

September 25, 2026

Vector Database Security for RAG: Isolation, Access and Poisoning

A practical guide to securing vector databases used by RAG systems, including tenant isolation, ingestion controls, authorization, poisoning tests and evidence.

Read more

September 25, 2026

RAG Poisoning Security: How Malicious Documents Manipulate AI Agents

Understand and test RAG poisoning across document ingestion, retrieval, prompt injection, metadata, agent tools, memory and source remediation.

Read more

September 25, 2026

Multi-Agent Security: Trust, Delegation and Confused Deputies

Threat model multi-agent systems across delegation, agent identity, message provenance, capability transfer, compromised peers and end-to-end evidence.

Read more

September 25, 2026

MCP Sampling Security: When Servers Request Model Completions

How to secure MCP sampling against prompt injection, data disclosure, model misuse, recursive calls, cost abuse and unsafe server-directed completions.

Read more

September 25, 2026

MCP Remote Server Security: An Enterprise Deployment Checklist

Secure remote MCP servers across transport, identity, authorization, tool governance, tenancy, egress, observability, deployment and incident response.

Read more

September 25, 2026

Local MCP Server Security: Stdio, Filesystem and Process Risks

A practical security guide for local MCP servers covering stdio transport, process execution, filesystem access, environment secrets, trust and endpoint containment.

Read more

September 25, 2026

MCP Elicitation Security: Protecting User Input and Sensitive Data

How to secure MCP elicitation flows against deceptive prompts, sensitive-data collection, schema abuse, consent confusion and untrusted server requests.

Read more

September 25, 2026

MCP Authorization Security: OAuth, Token Audience and Confused Deputies

A practical guide to securing MCP authorization across OAuth discovery, token audience, consent, delegation, confused-deputy attacks and downstream access control.

Read more

September 25, 2026

LLM-as-a-Judge Security: Reliability, Prompt Injection and Evidence

Secure LLM-as-a-judge systems against prompt injection, bias, context loss and false confidence while preserving reviewable evidence for AI testing.

Read more

September 25, 2026

Healthcare AI Agent Security: Protecting Patient Data and Clinical Workflows

A practical security guide for healthcare AI agents across patient isolation, clinical data, tools, approvals, evidence, availability and safe testing.

Read more

September 25, 2026

AI Agent Tenant Isolation: Security Testing for Multi-Tenant SaaS

Test multi-tenant AI agents for cross-customer leakage across authentication, RAG, memory, tools, caches, files, logs and delegated actions.

Read more

September 25, 2026

AI Agent Secrets Management: Tokens, Keys and Credential Brokers

Secure AI agent credentials with workload identity, short-lived tokens, credential brokers, least privilege, redaction, rotation and adversarial testing.

Read more

September 25, 2026

AI Agent Privilege Escalation: Attack Paths and Security Testing

Test AI agents for privilege escalation through tools, identities, approvals, prompt injection, delegation, role confusion and vulnerable downstream services.

Read more

September 25, 2026

AI Agent Penetration Testing: A Complete Methodology

A practical AI agent penetration-testing methodology covering scope, threat modeling, prompt injection, RAG, memory, tools, identity, evidence and retesting.

Read more

September 25, 2026

Least Privilege for AI Agents: Tools, Data and Delegated Authority

Apply least privilege to AI agents across workload identity, user delegation, tools, data, sessions, approvals and dynamic task-level authorization.

Read more

September 25, 2026

AI Agent Kill Switches: Emergency Controls and Safe Shutdown

Design and test AI agent kill switches across sessions, tools, credentials, queues, memory and downstream actions without creating a false sense of control.

Read more

September 25, 2026

Human-in-the-Loop Security for AI Agents: Approval That Actually Works

Design secure AI-agent approvals that show trusted parameters, resist prompt injection, prevent replay and match the consequence of each action.

Read more

September 25, 2026

AI Agent Guardrail Testing: How to Measure Real Security Boundaries

Test AI agent guardrails across input, output, retrieval, tools, identity and downstream effects without confusing detection scores with security validation.

Read more

September 25, 2026

AI Agent Data Exfiltration: Attack Paths, Detection and Testing

How AI agents leak data through responses, tools, URLs, messages, logs and memory—and how to test egress controls with safe canaries and evidence.

Read more

September 25, 2026

Agentic Commerce Security: Protecting AI-Initiated Payments and Purchases

A security guide for AI agents that search, negotiate, purchase, pay or issue refunds, covering intent, authorization, tools, evidence and adversarial testing.

Read more

September 19, 2026

AI SOC Agent Security: Investigation and Response Risks

Secure SOC and incident-response agents against poisoned alerts, excessive access, unsafe remediation, data leakage and adversarial tool use.

Read more

September 19, 2026

AI Coding Agent Security: Repositories, Secrets and CI/CD

Secure AI coding agents against repository prompt injection, CI/CD secret theft, unsafe shell execution, excessive permissions and supply-chain attacks.

Read more

September 19, 2026

AI Agent Supply-Chain Security: Skills, MCP and Plugins

Learn how malicious skills, plugins, MCP servers and packages enter the AI agent supply chain—and how enterprises can govern and test them.

Read more

September 19, 2026

AI Agent Skills Security: A Pre-Installation Guide

Review AI agent skills for malicious instructions, unsafe scripts, excessive permissions, hidden dependencies, update risk and prompt injection.

Read more

September 19, 2026

AI Agent Observability: What Security Teams Must Monitor

Learn which prompts, identities, retrieval events, memory changes, tool calls and downstream effects security teams should monitor across AI agents.

Read more

September 19, 2026

AI Agent Sandbox Security: A Practical Containment Guide

Contain AI agents across filesystem, network, identity, tools and approval boundaries with a practical defense-in-depth testing guide.

Read more

September 19, 2026

AI Agent Incident Response: An Enterprise Forensics Playbook

Contain compromised AI agents, preserve prompt and tool evidence, scope impact, recover safely and prevent recurrence with this enterprise playbook.

Read more

September 19, 2026

AI Agent Bill of Materials: An Enterprise AIBOM Guide

Build an AIBOM across AI models, prompts, data, memory, skills, MCP servers, tools, identities, policies and software dependencies.

Read more

August 20, 2026

MCP Gateway Security: Architecture, Controls and Testing

What an MCP gateway is, how secure gateway architecture works, and how to evaluate identity, tool governance, egress, bypass resistance and testing.

Read more

August 20, 2026

AI Browser Security: How to Test Agentic Browsers Before Enterprise Rollout

A practical enterprise guide to testing agentic browsers for indirect prompt injection, authenticated-session abuse, unsafe navigation, downloads, uploads, approvals, and data leakage.

Read more

August 20, 2026

AI Agent Framework Security: When Prompt Injection Reaches Trusted Code

How untrusted agent content can cross into framework serialization, caching, parsers, memory, and execution paths—and how enterprises should test and contain the risk.

Read more

August 14, 2026

NSA MCP Security Guidance: An Enterprise Implementation Checklist

A practical interpretation of the NSA's 2026 MCP security design guidance, covering architecture, trust, identity, tool controls, data protection, monitoring, and validation.

Read more

August 14, 2026

MCP Security Changes: An Enterprise Migration Guide

What the latest MCP specification changes mean for security teams, including stateless requests, authorization hardening, routing headers, cache scope, Tasks, Apps, and migration testing.

Read more

August 14, 2026

AI Agent Authentication and Authorization: A Zero-Trust Guide

How enterprises can authenticate AI agents, implement fine-grained authorization, constrain delegated authority and audit tool-using systems.

Read more

August 14, 2026

AI Agent Hijacking: How to Test Email, Web and Code Workflows

A practical guide to testing indirect prompt injection and agent hijacking across email, browsing, documents, code repositories, tools, memory, and high-impact actions.

Read more

August 14, 2026

A2A Security: Threat Modeling Agent-to-Agent Communication

A practical security guide to A2A Agent Cards, authentication, delegation, task ownership, artifacts, multi-agent trust boundaries, and evidence-driven testing.

Read more

August 11, 2026

How to Evaluate MCP Security Vendors: Capabilities, Testing Depth and Evidence

A practical buyer's guide to evaluating MCP security vendors across coverage, behavioral testing, evidence quality, deployment safety, and proof-of-value design.

Read more

August 8, 2026

How to Threat Model an AI Agent: Application, RAG, Memory, Tools, and Identity

A step-by-step method for threat modeling production AI agents across application, model, RAG, memory, tools, MCP, identity, approvals, and infrastructure boundaries.

Read more

August 8, 2026

Shadow AI Agents: How Enterprises Can Discover and Assess Unsanctioned Agents

A practical guide to shadow AI agents: where unsanctioned agents appear, why they create security risk, how to build an inventory, triage exposure, and assess high-impact systems.

Read more

August 8, 2026

OWASP Top 10 for Agentic Applications: A Practical Security Testing Guide

A practical guide to the OWASP Top 10 for Agentic Applications, with attack examples, testing questions, evidence requirements, and remediation priorities for enterprise AI agents.

Read more

August 8, 2026

OWASP MCP Top 10 Explained: Risks, Examples, and a Security Testing Checklist

A practical guide to the OWASP MCP Top 10, with realistic attack examples, test objectives, evidence requirements, and defensive priorities for MCP servers and connected AI agents.

Read more

August 8, 2026

NIST AI Agent Security Guidance: What Enterprise Teams Should Do Now

An enterprise interpretation of current NIST work on AI agent security, with practical actions for inventory, identity, tool control, evaluation, monitoring, and incident readiness.

Read more

August 8, 2026

MCP Tool Poisoning Explained: How Malicious Tool Descriptions Hijack AI Agents

Learn how MCP tool poisoning works, why tool metadata becomes an instruction channel for AI agents, how attacks spread across servers, and how to test and reduce the risk.

Read more

August 8, 2026

Indirect Prompt Injection in RAG and Tool-Using Agents: Attack Paths and Defenses

A technical guide to indirect prompt injection in RAG applications and tool-using agents, including realistic attack paths, safe testing methods, evidence, and layered defenses.

Read more

August 8, 2026

Excessive Agency in AI Systems: When Tool Access Becomes a Security Risk

Learn what excessive agency means in AI systems, how over-scoped tools and identities create real impact, how to test safely, and which controls reduce autonomous risk.

Read more

August 8, 2026

AI Agent Security Checklist for Production Deployments

A production-focused AI agent security checklist covering ownership, data, RAG, memory, tools, MCP, identity, approvals, testing, monitoring, and incident response.

Read more

August 8, 2026

AI Agent Security for Banking: Authentication, Access and Controls

How banks can secure agentic AI across customer identity, open-banking access, transactions, RAG, tools, approvals, testing and audit evidence.

Read more

August 8, 2026

AI Agent Red Teaming vs LLM Testing and Evaluations

Compare AI agent red teaming, LLM security testing and model evaluations—and learn when each method provides useful evidence for production systems.

Read more

August 8, 2026

AI Agent Memory Poisoning: How Persistent Context Creates Long-Lived Attacks

A practical guide to AI agent memory poisoning, cross-session leakage, persistent instruction attacks, safe testing, memory isolation, incident response, and remediation.

Read more

August 7, 2026

MCP Security Testing: How to Assess Tools Before Agents Use Them

MCP servers expand what AI agents can do, but they also expand the security surface. Learn how to test exposed tools, unsafe arguments, authorization boundaries, and excessive agency before agents rely on them.

Read more

August 7, 2026

AI Agent Security vs WAFs: Why Web Controls Are Not Enough

WAFs and API gateways remain useful, but they do not validate model behavior, RAG boundaries, tool selection, MCP misuse, or multi-turn agent workflows. AI agents need complete implementation security testing.

Read more

August 5, 2026

How to Test RAG Applications for Data Leakage

RAG applications can expose private context, source metadata, and cross-tenant data when retrieval boundaries fail. Learn how security teams should test RAG systems through the application interface.

Read more

August 3, 2026

The CISO's Guide to Agentic AI Security Validation

Autonomous AI agents create a wider security surface than chatbots or standalone models. CISOs need a validation framework that covers applications, APIs, prompts, RAG, memory, tools, MCP, and permission boundaries.

Read more

August 1, 2026

Prompt Injection Testing Is Not Enough

Prompt injection is only one part of the agentic AI attack surface. Enterprise teams need to validate the full implementation: application, API, model behavior, RAG, memory, tools, MCP, and permission boundaries.

Read more

July 28, 2026

Announcing Oxyne: Security for the Agentic Enterprise

Our platform has a new name and a sharper focus: validating complete agentic AI implementations and the boundaries that shape their real impact.

Read more

July 15, 2026

MCP Servers Need Their Own Threat Model

Treating an MCP server like a REST API during a pentest misses the failure modes that actually matter: tool-selection abuse, over-broad tool scopes, and cross-tool data leakage.

Read more