Skip to main content

tags

CyberSecurity

Browse Pomerium articles tagged CyberSecurity.

Topic archive

Resources Tagged: CyberSecurity

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
blog posts

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included

Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."

Understanding Anthropic's Zero Trust for AI Agents Guide
blog posts

Understanding Anthropic's Zero Trust for AI Agents Guide

Most writing about AI agent security stops at the scary part: agents can be prompt-injected, they hold credentials, they act near production. True, and not very useful. However, the implementation half of Anthropic's Zero Trust for AI Agents guide is more interesting because it stops describing the problem and starts grading the solutions. It lays out exactly which controls count as table stakes, which are enterprise-grade, and which are reserved for the highest-stakes environments.

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust
blog posts

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust

The Register reported today that CVE-2026-0257 , an authentication bypass in Palo Alto's GlobalProtect, has moved from a quiet medium-severity advisory to confirmed exploitation in the wild. Rapid7 traced successful attacks back to at least May 17 and reproduced the technique themselves. The flaw now sits in CISA's Known Exploited Vulnerabilities catalog with a same-day patch deadline for federal agencies.

When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access
blog posts

When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access

As autonomous AI agents fan out across the open web to read pages, call tools, and drive workflows on our behalf, the web itself becomes the attack surface. The adversary no longer needs to compromise the model, the endpoint, or the user. They only need to shape the information the agent sees. The DeepMind team calls this new class of adversarial content AI Agent Traps , and their paper is the first systematic taxonomy of them.

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
blog posts

Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026

The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?

Why Identity-Aware Access is the Missing Layer in Agentic Security
blog posts

Why Identity-Aware Access is the Missing Layer in Agentic Security

A new VentureBeat analysis from this week lands on a truth that every enterprise security team already feels in their gut: most AI agents are a credential exfiltration waiting to happen. The monolithic agent pattern — where reasoning, execution, credential storage, and tool access all share the same process — creates a threat surface that conventional security tooling wasn't designed to close.

MCP Server Security Risks: What Development Teams Need to Know in 2026
blog posts

MCP Server Security Risks: What Development Teams Need to Know in 2026

MCP servers give AI agents direct access to your internal systems—databases, APIs, file systems—through a standardized protocol. That's powerful for building agentic workflows, but it also creates attack vectors that traditional security tools weren't designed to handle. Gartner predicts 25% of enterprise breaches by 2028 will trace back to AI agent abuse.

7 Things to Know About Kubernetes Health Checks
blog posts

7 Things to Know About Kubernetes Health Checks

At Pomerium, we help organizations run secure and resilient systems on Kubernetes. Health checks are a critical part of that work, yet they’re often difficult to configure effectively. As we expand our deployment and observability practices, we’ve been refining how we think about health checks, why they’re challenging, and the patterns that lead to reliability across different customer environments.

8 Docker Image Scanning Tools: 2025 and Beyond
blog posts

8 Docker Image Scanning Tools: 2025 and Beyond

In the previous article, we explored the top 10 Docker container scanning tools . Now, we will shift our attention to Docker image scanning tools. While many tools offer both image and container scanning capabilities, this isn't always the case—some are specialized in just one area. In this article, we’ll dive into the top Docker image scanning tools and their unique features.

How Pomerium Supports FedRAMP Compliance
blog posts

How Pomerium Supports FedRAMP Compliance

Recently, we’ve had a lot of conversations with folks regarding whether or not Pomerium has achieved FedRAMP. We wanted to take some time to point out that while FedRAMP doesn’t apply to self-hosted software like Pomerium Core or Enterprise, there are actually specific parts of NIST SP 800-53 and FedRAMP compliance requirements that Pomerium can help you achieve.

12 Zero Trust Architecture Examples With Actionable Guide
blog posts

12 Zero Trust Architecture Examples With Actionable Guide

At this stage, it's safe to assume you're familiar with the core principle of Zero Trust Architecture: "never trust, always verify." Zero Trust is a framework, not a single tool you can install. So, what does a real-world zero-trust architecture example look like? What tools are necessary to achieve full zero trust implementation? In this article, we have presented a zero-trust architecture example to illustrate how a fully secured organization operates and included 12 additional zero-trust examples highlighting the features and tools required for 360-degree zero-trust protection.

What is Zscaler and How Does it Work?
blog posts

What is Zscaler and How Does it Work?

If you’re evaluating a shift from traditional VPNs and considering Zscaler, this article will help. Here, we have explored what is Zscaler and how it works, its offerings, cost, pros, and cons. We have also covered how ZPA works as a VPN replacement and compared it to a promising alternative—Pomerium. Let’s begin.

Identity Aware Proxy (IAP): Meaning, Pricing, Solutions
blog posts

Identity Aware Proxy (IAP): Meaning, Pricing, Solutions

If you’re looking to implement a zero-trust model for your organization, you’ve probably encountered the term “Identity-Aware Proxy” or “ IAP .” But what does it really mean? Which tools are best for implementing it? Is it affordable for small to medium-sized businesses, or does it come with a hefty price tag? In this article, we answer all these questions about identity-aware proxy with real-life examples. Let’s explore.

Zscaler vs. Tailscale vs. Pomerium: Detailed Comparison
blog posts

Zscaler vs. Tailscale vs. Pomerium: Detailed Comparison

If you have shortlisted Zscaler, Tailscale, and Pomerium to implement an efficient IAM solution for your distributed teams and remote infrastructure, this comparison guide will help you make a well-informed final decision. In this article, we will compare eight core features of Zscaler, Tailscale, and Pomerium to give you a comprehensive analysis of their core strengths, limitations, pricing, and ideal use cases. Let’s begin.

5 Top Tailscale Alternatives: Open Source and Paid
blog posts

5 Top Tailscale Alternatives: Open Source and Paid

If you're exploring alternatives to Tailscale, this guide is here to help. Securing remote access through VPNs remains a popular method for many organizations, but not all VPNs are the same. Different types offer various features, and there are even alternatives to traditional VPNs that provide enhanced security with reduced latency.

Kubectl Cheat Sheet with Examples- 50 Quick Commands
blog posts

Kubectl Cheat Sheet with Examples- 50 Quick Commands

Whether you're a seasoned DevOps engineer or just getting started with Kubernetes, having a quick reference guide can significantly boost your productivity and confidence. In this article, we've created an ultimate Kubectl cheat sheet with 50 essential commands and examples, covering everything from basic operations to advanced configurations. This guide is designed to be your go-to resource for navigating Kubernetes efficiently, helping you execute tasks faster and with greater accuracy.

Cloudflare Access vs. Tailscale vs. Pomerium
blog posts

Cloudflare Access vs. Tailscale vs. Pomerium

If you have shortlisted Cloudflare Access, Tailscale, and Pomerium for your ZTNA needs but are unsure which one to choose, this article is here to guide you. These three solutions follow Zero Trust principles but vary significantly in architecture, features, and ideal use cases. This Cloudflare Access vs. Tailscale vs. Pomerium guide contains a detailed comparison of each to help you better understand their differences and make a more informed decision about your organization's security requirements.

Cloudflare Alternatives & Competitors: CDN, Zero Trust & SASE
blog posts

Cloudflare Alternatives & Competitors: CDN, Zero Trust & SASE

Cloudflare offers a wide range of services, making it difficult to find a single alternative that covers all its capabilities. In this article, we've outlined Cloudflare alternatives for 1) Zero Trust and Secure Access Service Edge (SASE) , and 2) Application and Network Services, allowing you to make an informed decision based on your specific needs. So, without further delay, let’s explore!

Kubernetes Compliance: NIST, CIS & PCI- Actionable Guide
blog posts

Kubernetes Compliance: NIST, CIS & PCI- Actionable Guide

Achieving Kubernetes compliance requires a careful blend of technical controls, governance policies, and security best practices. To help you in this process, we have compiled an actionable guide for Kubernetes PCI compliance, NIST container security, and CIS Kubernetes benchmark. By leveraging these best practices and tools, organizations can confidently secure their Kubernetes environments and maintain regulatory compliance.

Zero Trust VPN: Meaning and Alternatives
blog posts

Zero Trust VPN: Meaning and Alternatives

Zero Trust VPN means a virtual private network service that works on the principle of "never trust, always verify." Although some VPN providers claim to offer Zero Trust VPN, in reality, most VPNs lack some core features and the users need to buy extra security products/services to implement the Zero Trust model.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo