authors
Bobby DeSimone
Bobby DeSimone articles and resources from Pomerium.
Founder & CEO
Bobby is the founder and CEO of Pomerium.

Topic archive
More from Bobby DeSimone

Announcing Pomerium v0.32
Pomerium v0.32.0 is all about less friction and more control: SSH access now uses the standard OAuth Authorization Code flow, onboarding can start with a hosted IdP, MCP token refresh is automated, and operators get clearer visibility into databroker state. We also tightened DNS controls and polished a few operational edges.

Hosted Clusters in Pomerium Zero & MCP Hacking (endpoints from localhost via ssh)
If you’re building an MCP server and you want a public model (ChatGPT, Claude, or Gemini) to actually call it, you hit the same wall: All the frontier models need a public HTTPS URL.

It’s always DNS part ∞: tracking down a use-after-free bug in Envoy’s DNS Resolver
We found a use-after-free bug in Envoy’s DNS resolver, c-ares (CVE-2025-62408, CVE-2025-67514).
When AI Has Root: Lessons from the Supabase MCP Data Leak
In a post by Simon Willison , we saw a lethal trifecta in action: an LLM agent with broad database privileges was tricked by a user's support-ticket text into exfiltrating secrets. The scenario with Cursor (a Claude-based IDE) and Supabase's new Model Context Protocol (MCP) is eerily simple but deadly: the developer's LLM agent runs with the full service_role key, bypassing all Row-Level Security (RLS). It ingests customer support messages as input. An attacker files a ticket containing hidden instructions like:
Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.
5 Reasons Chief Information and Technology Officers Are Rewriting Access Strategies for AI in 2025
Autonomous agents are here, and they’re reshaping enterprise systems. Agentic access is changing the rules — and legacy models aren’t ready for what’s coming next.
Announcing Pomerium v0.29.0
Pomerium v0.29.0 brings major enhancements to secure access and user experience. This release focuses on improved observability , expanded support for non-HTTP protocols , and a more user-friendly access portal , alongside critical authentication and policy improvements. From unified OpenTelemetry tracing to identity-aware UDP tunneling , Pomerium v0.29.0 makes it easier to monitor, connect, and manage your infrastructure. This release also includes performance optimizations, developer-focused refinements, and important breaking changes to be aware of when upgrading.

What is a "Pomerium"?
When I first started developing the idea for Pomerium, choosing the name wasn’t just an afterthought—it was a deliberate decision to align the company’s mission with a concept that’s both historically significant and deeply relevant to the challenges of modern cybersecurity.

The Great VPN Myth: What PCI DSS 4.0 Actually Requires for Remote Access
"We can’t use Pomerium - we need a VPN for PCI compliance."

Announcing Pomerium v0.28
Pomerium v0.28 brings new features, performance improvements, and quality of life upgrades to our zero trust reverse proxy.
Announcing Pomerium v0.18
We are excited to announce the v0.18 release of Pomerium! This release features support for external data sources, an integral component of zero trust architecture. Without further ado, let’s get down to what it is, why it’s important, and how you can use it!

The Far Reach of the White House’s Zero Trust Memo
The new White House memo on zero trust is a strong signal that the US federal government is taking an active stance regarding cybersecurity. Not only does this have far-reaching ramifications for the public and private sectors, it also serves to cut through the noise about zero trust with an impartial source. Let’s look at what the White House has to say and what this means for the cybersecurity sector going forward.
Pomerium Completes Independent Security Audit by Cure53
We take the security of Pomerium seriously. In addition to our open source codebase and public security, and disclosure policies , we also understand the need for periodic security assessments and penetration testing from reputable third parties. We are pleased to announce that Pomerium has completed a thorough security audit and analysis from the security experts at Cure53 .
Announcing Pomerium Enterprise General Availability
We are pleased to announce the general availability of Pomerium Enterprise! Pomerium is widely used by individuals and teams at companies large and small as the standard for identity-aware access. We’ve been working with our design partners on an enterprise version of Pomerium that we are thrilled to be finally able to share with you today.
Pomerium 0.14
We are excited to announce Pomerium version 0.14 ! This release adds new identity provider support, high-availability capabilities, and major performance improvements.
Pomerium 0.13
We are excited to announce Pomerium version 0.13 ! This release enhances Pomerium’s capabilities as a first-class, fully featured, edge proxy. Some highlights include:
Pomerium 0.12
We are excited to announce the 0.12 release of Pomerium!
Pomerium 0.11
We are excited to announce Pomerium 0.11 , a minor release focused on improving the core capabilities, performance, and stability of Pomerium.

Pomerium 0.10
We are excited to announce version 0.10 of Pomerium! Highlights of this release include:

Pomerium 0.9
We are excited to announce the 0.9 release of Pomerium which includes a complete refactor of the proxy service and several security-enhancing features. Those features include:

Pomerium 0.8
We are excited to announce the 0.8 release of Pomerium which adds support for some of our most requested features including:

Pomerium 0.7
The 0.7 release of Pomerium lays the groundwork to support rich, dynamic access policies capable of making authorization decisions based on external data-sources from outside your identity provider.
