<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ZuluSec field notes</title><description>Security teardowns of real misconfigurations and their fixes, and Blueprint explainers that describe an architecture in plain English.</description><link>https://zulusec.com/</link><language>en-us</language><item><title>A reference architecture for agents that work the way your people do</title><link>https://zulusec.com/blog/agent-operations-platform-reference-architecture/</link><guid isPermaLink="true">https://zulusec.com/blog/agent-operations-platform-reference-architecture/</guid><description>What becomes possible when the boundary comes first: a person asks for work in plain words, an agent does it in a machine that exists only for that session, everything it touches belongs to somebody, and the record shows what happened. The five planes, two worked flows, and where to start.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>ai agents</category><category>reference architecture</category><category>sandboxing</category><category>firecracker</category><category>containment</category></item><item><title>Ambient authority is the bug, and WebAssembly makes you name it</title><link>https://zulusec.com/blog/ambient-authority-webassembly/</link><guid isPermaLink="true">https://zulusec.com/blog/ambient-authority-webassembly/</guid><description>Every containment control is a fence built around a runtime that defaults to yes. WebAssembly inverts that, but it does not remove the problem so much as force it into writing, and the places it leaks are worth knowing before you bet an architecture on it.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>webassembly</category><category>rust</category><category>capability security</category><category>architecture</category><category>containment</category></item><item><title>AI agent sandboxes, and what actually holds</title><link>https://zulusec.com/blog/ai-agent-sandboxes-explained/</link><guid isPermaLink="true">https://zulusec.com/blog/ai-agent-sandboxes-explained/</guid><description>Everyone is putting agents in sandboxes. Most of the machinery being written about today will be obsolete in two years. Here are the properties that will not be, and a public harness that tells you whether your sandbox enforces them.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate><category>ai agents</category><category>sandboxing</category><category>zero trust</category><category>architecture</category><category>containment</category></item><item><title>How one Kubernetes misconfiguration hands over your whole cluster</title><link>https://zulusec.com/blog/kubernetes-anonymous-cluster-takeover/</link><guid isPermaLink="true">https://zulusec.com/blog/kubernetes-anonymous-cluster-takeover/</guid><description>Bind a powerful role to the anonymous identity and any request with no credentials can read every secret and run any workload. Here is the attack, the fix, and the one command that tells you where your own cluster stands.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate><category>Kubernetes</category><category>RBAC</category><category>cloud security</category><category>DevSecOps</category></item><item><title>Prompt injection in agent workflows, explained</title><link>https://zulusec.com/blog/prompt-injection-agent-workflows/</link><guid isPermaLink="true">https://zulusec.com/blog/prompt-injection-agent-workflows/</guid><description>An AI agent has no boundary between the instructions you gave it and the text it reads. Anything it reads can try to become an instruction. Here is the model in plain English, why filtering does not fix it, and the gates that actually hold.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>prompt injection</category><category>ai agents</category><category>automation</category><category>architecture</category></item><item><title>Your S3 bucket is public and you probably don&apos;t know it</title><link>https://zulusec.com/blog/public-s3-bucket-customer-data/</link><guid isPermaLink="true">https://zulusec.com/blog/public-s3-bucket-customer-data/</guid><description>S3 buckets are private by default, so a public one is a wrong setting left on by accident. Here is how anyone downloads the data, how to find every public bucket you own, and the one setting that stops it.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>AWS</category><category>S3</category><category>data exposure</category><category>cloud security</category></item><item><title>Your deleted AWS key is still in your git history</title><link>https://zulusec.com/blog/deleted-aws-key-git-history/</link><guid isPermaLink="true">https://zulusec.com/blog/deleted-aws-key-git-history/</guid><description>Deleting a leaked AWS key from your code does not remove it. Here is how attackers find keys in git history, what one key exposes, and the three fixes that actually work.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>AWS</category><category>secrets</category><category>DevSecOps</category><category>cloud security</category></item><item><title>Zero trust architecture, explained without the buzzwords</title><link>https://zulusec.com/blog/zero-trust-architecture-explained/</link><guid isPermaLink="true">https://zulusec.com/blog/zero-trust-architecture-explained/</guid><description>Zero trust is not a product you buy. It is one idea: stop trusting the network, and check every request instead. Here is the whole model in one diagram, in plain English, and where to actually start.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>zero trust</category><category>architecture</category><category>identity</category><category>network security</category></item></channel></rss>