blog.live
Blog

Agent security, in depth.

Research, guides, and commentary on AI agent security from the Wing team.

July 13, 2026

GitLost isn’t a bug but it is your problem

When researchers disclosed GitLost, a critical prompt injection vulnerability within GitHub’s new Agentic Workflows on July 7, the headlines made it sound like a bug. But the real story is about agent permissions, access and authorization. GitLost exposed a much broader security problem that extends far beyond GitHub: AI agents are operating with legitimate access […]

Read post →
July 2, 2026

Agentic AI Governance: The InfoSec Guide

Abstract: Agentic AI governance gives InfoSec teams a way to discover which agents exist, who owns them, what identities and permissions they rely on, what actions they take, and whether their behavior still matches their intended purpose.  This guide explains how security teams can: Discover which AI agents exist across the environment Identify who owns […]

Read post →
June 21, 2026

AI Agent Security: An Essential Guide

Abstract: AI agent security is the practice of discovering, governing, and controlling AI agents that can access systems, use tools, trigger workflows, interact with SaaS apps, and act through user-delegated sessions, service accounts, OAuth grants, API keys, or other non-human identities.  This guide covers: How AI agent security works  Why agents create new identity and […]

Read post →
June 10, 2026

10 AI Agent Security Best Practices to Implement Today

Chances are, your organization has AI agents running right now with access levels that your security team didn’t approve. In fact, even the agent’s user didn’t approve them.   Today, 79% of senior executives report AI adoption, yet 92% are concerned about the security implications. Gartner expects 40% of enterprise applications will embed task-specific agents (up […]

Read post →
June 9, 2026

15 Top Tools for Monitoring Non-Human Identity Activity

Tools for monitoring non-human identity activity help security teams discover, inventory, govern, and investigate the activity of machine identities, service accounts, OAuth apps, API keys, workload identities, integrations, and AI agents. Top Monitoring Non-Human Identity Activity Tools Include: Wing Security Cyberhaven MCPTotal / Autonomous Security Operant AI Endpoint Protector Akeyless GitGuardian Entro Security Astrix Security […]

Read post →
May 31, 2026

Why Every Enterprise Needs an AI Agent Inventory

Artificial intelligence is no longer limited to chatbots and productivity assistants. Across organizations, employees are building, deploying, and sharing AI agents that can access business data, make decisions, trigger workflows, and act on behalf of users. What started as experimentation has quickly evolved into a new operational layer inside the enterprise. Today, employees can create […]

Read post →
May 6, 2026

How an AI Agent Wiped 5 Years of Data in 9 Seconds and Why You Should Care

AI agents are quickly becoming part of the modern development stack. They write code, fix bugs, run commands, and increasingly interact with production environments. For many teams, they are already embedded in daily workflows. But what happens when those agents make the wrong decision? A recent incident involving PocketOS, a SaaS platform serving rental businesses, […]

Read post →
April 30, 2026

How to Use n8n Workflows Without Risking a Breach

Automation has quietly become the backbone of modern operations. Tools like n8n make it easy to connect SaaS applications, orchestrate workflows, and even build AI-driven processes with very little friction. Teams can move faster, eliminate repetitive work, and unlock new efficiencies across the business. That same flexibility is exactly what creates risk. n8n is powerful […]

Read post →
April 12, 2026

What Every CISO Should Know About OWASP for AI Security

Traditional security models were not designed for systems where inputs can alter behavior, identities are non-human, and decision-making is probabilistic. When it comes to frameworks for managing agentic AI safely, the OWASP GenAI Security Project cannot be overlooked. Here’s why. The OWASP GenAI security project story Originally launched in 2023 as the OWASP Top 10 […]

Read post →
April 6, 2026

Why a “Kill Switch” for AI Agents Won’t Save You

The idea of a “kill switch” for AI agents is a popular talking point in cybersecurity. It sounds reassuring: if an AI agent misbehaves, goes rogue, or gets compromised, you simply shut it down. Problem solved. But this framing is incomplete in a way that should concern security leaders. A kill switch is not a […]

Read post →
March 19, 2026

5 Challenges AI Adoption Managers Face When Scaling AI Agents

AI agents are quickly moving from experimentation to real business workflows. What started as small pilots is now expanding across teams, automating tasks in marketing, finance, operations, and product. For many organizations, the question is no longer whether to use AI agents. It is how to scale them. And that is where things start to […]

Read post →
February 24, 2026

Agentic AI in 2026: From Assistants to Insiders and Why Identity Security Can Fix It

AI inside the enterprise is changing fast. For years, AI tools helped employees write content, summarize documents, or answer questions. They were assistive. Useful, but contained. That boundary is disappearing. In 2026, agentic AI systems does not just respond to prompts. Agents take action. They provision access, trigger workflows, interact with third-party applications, and make […]

Read post →