NKNivethitha Kumaraveluinnebulablogs.com·Sep 20 · 13 min readThe current state of security for autonomous agents in the cloudThis post covers how different cloud providers (AWS, Azure, and GCP) productize parts of the agent runtime, and how to architect the rest yourself. Prompt injection is still intrinsic, so a hijacked p710JBMAM
NKNivethitha Kumaraveluinnebulablogs.com·Sep 5 · 10 min readSecurity-review the agent app the coding agent just shippedWhen a coding agent builds a a brand-new AI integration on your ecommerce site (for example), you often get a big PR and a short note that "auth and tool calling are done." If your job is to check the00
NKNivethitha Kumaraveluinnebulablogs.com·Sep 4 · 6 min readAgentic AI is evolving the WAFWhen a critical web vulnerability lands, the software patch often still needs days. Attackers do not wait that long. From January through June 2026, CrowdStrike observed that 88% of exploitation again00
NKNivethitha Kumaraveluinnebulablogs.com·Aug 31 · 10 min readAgent skills in security engineering: encoding the vulnerability triage loopWorking through the security queue, I keep hitting the same friction. A CVE lands with a CVSS 9.8 and a recommended library bump. Looks clear. Except: is this service actually internet-facing, or is i00
NKNivethitha Kumaraveluinnebulablogs.com·Aug 26 · 13 min readFrom Finding Bugs to Fixing Them: How Far Has AI Vulnerability Remediation Come?By August 2026, frontier labs (Google DeepMind, OpenAI, Anthropic) and AppSec startups have all shipped some version of autonomous vulnerability remediation, and every one of them stops at the same ga10