Skip to main content

categories

Agentic Access Management

Browse Pomerium articles in the Agentic Access Management category.

Topic archive

Resources Categorized: Agentic Access Management

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
blog posts

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included

Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
blog posts

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026

The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?

Why Identity-Aware Access is the Missing Layer in Agentic Security
blog posts

Why Identity-Aware Access is the Missing Layer in Agentic Security

A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.

September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears
blog posts

September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears

September was a month of contrasts for the Model Context Protocol (MCP). On the one hand, the ecosystem matured rapidly. On the other hand, a wave of reports underscored how quickly attackers are targeting these interfaces. Researchers warned of prompt‑injection attacks, backdoored packages and a raft of newly ranked vulnerabilities, while practitioners called for stronger identity flows, fine‑grained authorization and tighter governance.

August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth
blog posts

August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth

August was filled with vulnerabilities and developments in the agentic AI and Model Context Protocol (MCP) landscape. Multiple high‑severity remote‑code‑execution vulnerabilities demonstrated how easily malicious servers or modified configurations can hijack developer machines. Docker went so far as to label the MCP ecosystem a “security nightmare,” prompting calls for OAuth 2.1 authorization and zero‑trust practices. Meanwhile, vendors made notable releases and thought leaders explored the future of AI as adoption accelerates.

The OWASP Top 10 for LLMs and How to Defend Against Them
blog posts

The OWASP Top 10 for LLMs and How to Defend Against Them

TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.

Why Traditional Access Controls Fail in LLM Deployments
blog posts

Why Traditional Access Controls Fail in LLM Deployments

TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.

July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth
blog posts

July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth

A number of pivotal developments marked the agentic AI and Model Context Protocol (MCP) world this past July. Two critical remote‑code‑execution flaws, one in the widely used mcp‑remote tool and another in Anthropic’s MCP Inspector , highlighted the growing security risks of AI‑agent tooling. Meanwhile, vendors released new MCP servers and training programs, and the open‑source project announced a formal governance model to sustain its rapid growth. The compiled July headlines below capture both the promise and the perils of the evolving MCP ecosystem.

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
blog posts

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes

TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.

When AI Has Root: Lessons from the Supabase MCP Data Leak
blog posts

When AI Has Root: Lessons from the Supabase MCP Data Leak

In a post by Simon Willison , we saw a lethal trifecta in action: an LLM agent with broad database privileges was tricked by a user's support-ticket text into exfiltrating secrets. The scenario with Cursor (a Claude-based IDE) and Supabase's new Model Context Protocol (MCP) is eerily simple but deadly: the developer's LLM agent runs with the full service_role key, bypassing all Row-Level Security (RLS). It ingests customer support messages as input. An attacker files a ticket containing hidden instructions like:

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
blog posts

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)

It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo