Skip to main content

authors

Nikhil Balaraman

Nikhil Balaraman articles and resources from Pomerium.

Nikhil Balaraman

Topic archive

More from Nikhil Balaraman

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
blog posts

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included

Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."

Understanding Anthropic's Zero Trust for AI Agents Guide
blog posts

Understanding Anthropic's Zero Trust for AI Agents Guide

Most writing about AI agent security stops at the scary part: agents can be prompt-injected, they hold credentials, they act near production. True, and not very useful. However, the implementation half of Anthropic's Zero Trust for AI Agents guide is more interesting because it stops describing the problem and starts grading the solutions. It lays out exactly which controls count as table stakes, which are enterprise-grade, and which are reserved for the highest-stakes environments.

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust
blog posts

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust

The Register reported today that CVE-2026-0257 , an authentication bypass in Palo Alto's GlobalProtect, has moved from a quiet medium-severity advisory to confirmed exploitation in the wild. Rapid7 traced successful attacks back to at least May 17 and reproduced the technique themselves. The flaw now sits in CISA's Known Exploited Vulnerabilities catalog with a same-day patch deadline for federal agencies.

When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access
blog posts

When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access

As autonomous AI agents fan out across the open web to read pages, call tools, and drive workflows on our behalf, the web itself becomes the attack surface. The adversary no longer needs to compromise the model, the endpoint, or the user. They only need to shape the information the agent sees. The DeepMind team calls this new class of adversarial content AI Agent Traps , and their paper is the first systematic taxonomy of them.

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
blog posts

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026

The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?

Why Identity-Aware Access is the Missing Layer in Agentic Security
blog posts

Why Identity-Aware Access is the Missing Layer in Agentic Security

A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.

MCP Server Security Risks: What Development Teams Need to Know in 2026
blog posts

MCP Server Security Risks: What Development Teams Need to Know in 2026

MCP servers give AI agents direct access to your internal systems—databases, APIs, file systems—through a standardized protocol. That's powerful for building agentic workflows, but it also creates attack vectors that traditional security tools weren't designed to handle. Gartner predicts 25% of enterprise breaches by 2028 will trace back to AI agent abuse.

Replacing Ingress-NGINX: A Modern Approach to Secure Kubernetes Access
blog posts

Replacing Ingress-NGINX: A Modern Approach to Secure Kubernetes Access

For years, NGINX Ingress has been the default answer to a simple question: How do I get traffic into my Kubernetes cluster? It excels at Layer-7 routing, TLS termination, and traffic shaping, and for many workloads it remains a solid choice. But as Kubernetes has moved beyond hosting public-facing services and into powering internal platforms , the limitations of traditional ingress have become increasingly apparent.

How Pomerium Supports FedRAMP Compliance
blog posts

How Pomerium Supports FedRAMP Compliance

Recently, we’ve had a lot of conversations with folks regarding whether or not Pomerium has achieved FedRAMP. We wanted to take some time to point out that while FedRAMP doesn’t apply to self-hosted software like Pomerium Core or Enterprise, there are actually specific parts of NIST SP 800-53 and FedRAMP compliance requirements that Pomerium can help you achieve.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo