Blog
Field notes on agent identity, runtime policy, and securing autonomous AI.
MCP Is Now Stateless: A Guide to 2026-07-28
MCP 2026-07-28 removes the initialize handshake, sessions, and server-initiated requests. What changed at the wire level, and how to migrate a server or client.
-
Research Claude Code Permissions and Auto Mode: The 44 KB Rulebook You Can't Print
How Claude Code permissions and auto mode actually work: the five gates, the classifier's consent model, the rules no approval clears, and cross-session permission laundering.
-
Research Inside OpenAI's Hugging Face Breach: A Reward-Hacking Teardown
How an OpenAI model chained a zero-day to breach Hugging Face and steal a benchmark answer key, plus the isolation and identity controls that stop it.
-
Security AI Runtime Security: How to Protect Agents and GenAI Apps at Request Time
AI runtime security protects agents and GenAI apps at request time, when prompt injection, data leakage, and rogue tool calls actually happen, not at build time.
-
Engineering AI Gateway Benchmarks: Highflame vs LiteLLM vs Bifrost (2026)
AI gateway benchmarks on real timing: Highflame adds ~2 ms to the first token, answers 100% of 5,000 held conversations, and adds 17 ms to an MCP tool call.
-
Security AI Agent Incident Response: What to Do When an Agent Is Compromised
AI agent incident response starts with the blast radius: when a compromised coding agent spawns 50 subagents, revoke the entire delegation chain in one atomic step.
-
Engineering AI Gateway Load Testing: What Breaks at Concurrency (and How to Fix It)
AI gateway load testing on a two-host AWS rig: under a 5,000-connection rush, Highflame answers in 0.83s where LiteLLM takes 17 seconds and drops a third of calls.
Archive
45 TOTAL- Jun 22, 2026 Engineering Claude Code Sandboxing: How Anthropic Contains Coding Agents (and How to Cover Your Fleet)
- Jun 20, 2026 Product MCP Enterprise Managed Authorization (EMA): What It Is and How Highflame Supports It
- Jun 03, 2026 Engineering MCP Gateway, LLM Gateway, Agent Gateway: Three Gateways, One Decision Fabric
- Jun 01, 2026 Product Highflame + Tailscale Aperture Now Blocks Risky AI Traffic in Real Time
- May 19, 2026 Research Mission Drift: Why AI Agents Fail at Step 100
- May 04, 2026 Product The Uniformed Guard Problem: Why AI Agent Sandboxes Need Identity, Not Just Policy
- Apr 29, 2026 Security Your agent followed every rule. It still broke policy.
- Apr 22, 2026 Research When AI Monitors Betray You: The Failure of LLM-as-Judge Architectures
- Apr 15, 2026 Research Why Meta’s AI Alignment Director Couldn't Stop Her Own Agent, and How to Fix It
- Apr 10, 2026 Security Deconstructing “Agents of Chaos”: Failures Behind Autonomous Agent Attacks
- Apr 09, 2026 Product Who Sent You? Solving the Agent Identity Crisis with Highflame ZeroID
- Apr 08, 2026 Product Introducing ZeroID: Open Source Identity for Autonomous Agents
- Apr 02, 2026 Company Highflame Partners with Tailscale to Help Secure AI Agents at the Network Layer
- Mar 31, 2026 Security The LiteLLM Supply Chain Attack Wasn’t Just a Supply Chain Problem
- Mar 10, 2026 Product Traditional Authentication Isn’t Enough for Agent & MCP Security
- Mar 06, 2026 Engineering Securely Rolling Out Claude Cowork Across Your Organization
- Feb 24, 2026 Research Securing Intent : The Next Frontier in AI Agent Protection
- Jan 26, 2026 Engineering Unified Control Plane for Enterprise Code Agent Security
- Jan 19, 2026 Research Agent Context Graphs and Safe Autonomy
- Jan 12, 2026 Company Palisade is now available on Github Marketplace
- Jan 06, 2026 Company DeepContext: Defending Against Multi-Turn LLM Attacks with Context-Aware Guardrails
- Dec 18, 2025 Company Launching Palisade: Zero-Trust Security for the AI Model Supply Chain
- Oct 03, 2025 Security How We Built Highflame RedTeam: An Agent-Powered AI Red Teaming System
- Sep 24, 2025 Company Introducing Overwatch: Code Agent Security
- Sep 16, 2025 Engineering When Agents Chain Tools, The Risk Multiplies
- Sep 10, 2025 Company Announcing the Ramparts MCP Toolkit on Docker Hub
- Sep 03, 2025 Research Why Enterprise AI Agent Security Can’t Rely on Platform Providers Alone
- Aug 28, 2025 Company Highflame joins Coalition for Secure AI
- Aug 26, 2025 Engineering Securing the Bridge: Where AI meets Enterprise Data
- Aug 21, 2025 Research Why GPT-5’s Capabilities Are a Double-Edged Sword for Enterprise Security
- Aug 15, 2025 Research 5 Blackhat 2025 Takeaways on AI & Automation Security
- Jul 22, 2025 Company Announcing Ramparts: Securing MCP usage
- Jul 10, 2025 Company Why traditional DLP hurts LLM accuracy?
- May 30, 2025 Company Javelin Guard: Next-Generation Security Models
- May 13, 2025 Product AI Agent Authentication Security: Prevent Spoofing, Prompt Injection, and Abuse
- May 13, 2025 Research Top 5 Takeaways for CISOs from RSAC 2025:
- Apr 16, 2025 Company Enterprise Strategies for MCP Integration
- Apr 12, 2025 Company Highflame achieves SOC2 compliance
No articles match.