AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms find real problems at a scale no human team can match. But when you read the findings closely, a pattern emerges: agents talked into refunds, transfers, and data leaks they had standing authority to perform. Patching the prompt fixes one phrasing until the next model update. Constraining the authority fixes the class. The first job belongs to a red team platform. The second belongs to your runtime, and no scanner will do it for you.

In April 2026, General Analysis raised a $10M seed round on the strength of an uncomfortable demonstration: its adversarial agent attacked 55 live customer service bots and compromised 50 of them. Not lab models, but live systems with real customers and real tool access. This post is about the market behind that demonstration: who now automates the attacker’s role, what the attacks keep finding, and why the fix that lasts is runtime policy rather than a better prompt.

What an AI red team agent actually does

A traditional red team Continue reading

Fakta Unik Denman Cryobrine Corridor di Danau Lake Denman

Danau Lake Denman Basal Cryobrine Corridor merupakan salah satu fenomena alam yang semakin menarik perhatian para ilmuwan dan peneliti dalam beberapa tahun terakhir. Fenomena yang sering disebut dengan istilah denman cryobrine corridor ini merupakan bagian penting dalam studi iklim dan ekosistem ekstrem di Bumi. Artikel ini akan mengupas fakta-fakta unik seputar denman cryobrine corridor yang relevan hingga saat ini dan bagaimana keberadaannya memengaruhi riset ilmiah di berbagai disiplin ilmu.

Pendahuluan: Apa Itu Denman Cryobrine Corridor?

Denman cryobrine corridor adalah sebuah bagian unik dari sistem glester di sekitar Danau Lake Denman yang dikenal dengan kandungan air garam yang tinggi pada suhu yang sangat rendah. Fenomena ini muncul ketika air garam superdingin membentuk sebuah koridor alami di bawah permukaan es. Keunikan dari denman cryobrine corridor terletak pada kemampuan air garam tersebut bertahan dalam kondisi ekstrem tanpa membeku, sehingga menimbulkan potensi ekosistem mikroorganisme unik yang belum banyak dipahami oleh ilmu pengetahuan.

Saat ini, denman cryobrine corridor sangat menjadi fokus riset karena memberikan wawasan baru terkait adaptasi kehidupan di kondisi ekstrem hingga potensi eksplorasi astrobiologi di planet lain yang memiliki kondisi serupa, seperti Mars atau bulan-bulan es di tata surya.

Karakteristik Fisik Denman Cryobrine Corridor

Pada periode terbaru, penelitian menggunakan satelit dan teknologi bawah Continue reading

Misteri Fenomena Clearwater West Shock Vein Zone yang Menarik

Fenomena alam geologi menarik perhatian para ilmuwan dan penggemar sains di seluruh dunia, salah satunya adalah kawasan Clearwater West Shock Vein Zone. Hingga saat ini, fenomena tersebut masih menyimpan banyak misteri yang membuat para peneliti terus mendalaminya. Artikel ini akan membahas secara lengkap dan terbaru tentang fenomena Clearwater West Shock Vein, dari penemuan, karakteristik, hingga implikasi ilmiah dan lingkungan yang relevan pada kondisi saat ini.

Pendahuluan: Apa Itu Clearwater West Shock Vein?

Fenomena Clearwater West Shock Vein merupakan sebuah zona nirkon yang ditemukan di kawah Clearwater West, salah satu dari dua kawah yang saling berdekatan di Quebec, Kanada. Fenomena ini dikenal sebagai salah satu contoh nyata dari struktur geologi yang terbentuk akibat benturan meteorit raksasa ke permukaan bumi. Kawah Clearwater West sendiri membentang sekitar 26 kilometer dan dikenal sebagai salah satu situs krater tipe “dual impact” yang unik.

Zona shock vein atau urat kejut adalah lapisan tipis material yang terbentuk dengan pola patahan dan deformasi ekstrem karena tekanan dan suhu sangat tinggi pada saat terjadi benturan meteorit. Wilayah Clearwater West Shock Vein menjadi sangat penting sebagai lokasi studi untuk memahami lebih jauh mekanisme pembentukan material dan batuan akibat benturan luar angkasa.

Penemuan dan Studi Terkini di Kawah Clearwater West Continue reading

Say it once: introducing Bot Preference Sync

We’re constantly building for the different goals of our customers. Some customers want to optimize for discovery, while others want to protect their content with the strictest security policy. Among these differing policies, there are multiple ways to mitigate bot traffic. Some mechanisms simply state your preference, assuming best intent from crawlers, and other approaches actually lock down content by outright blocking with a Bot Management solution.

We recognize that it's cumbersome to maintain multiple layers of protection on your website. For example, there are cases in which your robots.txt states that a crawler is Disallowed from accessing your website, while your enforcement rules actually don’t block that crawler. When your stated preferences and your enforced rules disagree, some crawlers treat it as a basis to disregard your preferences or try to bypass your enforced rules.

A couple of years ago, Cloudflare announced an easier way to disallow AI training on your website by tackling two of these layers: a managed value of robots.txt that told a fixed list of major Training crawlers not to train on your content, along with edge-enforced blocks to Training crawlers. On July 1, 2026, we launched easier options to manage different kinds Continue reading

From all-or-nothing to task-based OAuth consent

Since June, developers have created thousands of third-party OAuth apps on Cloudflare, with more than a million authorizations since.  

OAuth makes delegated access possible. It lets applications act on a user’s behalf without asking them to handle long-lived credentials or hand over a password. That model works well when an application can describe its access needs with a small set of scopes. 

Developers use OAuth for SaaS integrations, internal tools, CLIs, and agents. Our permission model has become more granular over time to support better scoping of these different workflows. That is great for security, but it makes a purely all-or-nothing consent screen hard to justify.

Cloudflare OAuth already allows clients to request a subset of their configured scopes. But once the client made that request, the user could not narrow it any further on the consent screen. For the user on the consent screen, the experience was still an all-or-nothing one. If an application requested more access than a user was comfortable granting, their only options were to approve the full request, or deny outright. 

MCP servers are a good example of this. An MCP server might request a broad set of permissions, because in Continue reading

Hedge 316: AI Governance

Deploying AI for AI Ops, or even just for general use in your network, is very simple–but we often forget that these kinds of new technologies need to be governed. From privacy through cost, operators need to decide how to govern their AI deployments to control costs, ensure accuracy, measure productivity, and make certain these systems are being used effectively. Colin Cosgrove joins Russ and Tom to look at AI governance.
 

 
download

IPB206: Do IPv6 Mandates Work?

Nick Burgalio and Tom Coffeen discuss a Reddit post that had what appeared to be new federal guidance on IPv6 adoption. While it seems the timelines and guidelines haven’t changed, the post raises questions about the effectiveness of mandates in driving IPv6 adoption. They posit that enabling IPv6 is not just a technical requirement but... Read more »

TCG082: AI News Roundtable – Copyrights, AI Watermarks, and the Open Weight Debate

William Collins and Eyvonne Sharp dig into the latest AI headlines, from the largest copyright settlement in American history to stolen AI models and invisible watermarks on Claude output. Plus, they discuss why so many companies have rallied around NVIDIA’s support for open weight AI models. Our hosts also examine the biggest questions arising from... Read more »

A revisit of remote Spectre attacks on Cloudflare Workers

In 2021, we assessed remote Spectre attacks against Cloudflare Workers. Based on the results, we shipped a production defense called Dynamic Process Isolation (DyPrIs), which identifies maliciously looking scripts and isolates them into separate processes. Since then, newer techniques in the area of stabilizing Spectre attacks have been discovered. To understand if these techniques posed a threat to our Workers production environment, we decided to internally reassess the remote Spectre attack. Building an updated proof-of-concept on the production environment allowed us to empirically assess the risk of Spectre attacks under production workloads. 

To mount a successful side-channel attack in production, an external attacker has to overcome additional obstacles such as activity on shared hardware resources, interrupts, context switches, and coarse-grained timers. Our research uncovered a limitation in the implementation of DyPrIs and we managed to demonstrate a remote Spectre attack reliably leaking up to 12 bit/s with a 99% accuracy in the production environment of Cloudflare Workers. As a consequence of this research, we improved DyPrIs, integrated the V8 Sandbox and an in-process isolation mechanism to further reduce the risk of memory disclosure attacks. 

Today we are publishing a paper describing our findings, co-authored by Albert Pedersen, Haocheng Continue reading

New Tool – VLAN / QinQ Tag Overhead Calculator

New on the Network Tools page: a VLAN / QinQ Tag Overhead Calculator. It exists because of the same problem that led to the MTU / Encapsulation Overhead Calculator — vendors don’t agree on what a config knob actually means, and it costs you an afternoon before you find that out.

The history behind this one

The MTU tool exists because mtu isn’t the same number on every platform. Classic Cisco IOS treats it as the L3 payload size. Junos and IOS-XR fold the 14-byte Ethernet header into it. Same command, same-looking number, two different frames on the wire — and the failure mode is never an error message, it’s just silent fragmentation or a black-holed jumbo-frame flow that only shows up under load.

Worth Reading: On AI Coding and Its Discontents

A lot of AI-coding enthusiasts are making claims along the lines of “AI coding tools are like compilers; you supply intent, they translate it into code, and who ever looked at the machine-code output?” Unfortunately, there is a bit of a gap between hope and reality; traditional compilers were always deterministic, and are (after decades of development and bug-fixing) pretty much bug-free. AI coding tools are neither, and no amount of “agentic loops” will solve that.

1 2 3 3,897