Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

dzone.com
dzone.com > articles > secure-mcp-servers

Securing Model Context Protocol Servers

1+ hour, 15+ min ago   (1847+ words) I was showing off a support assistant I'd wired up over the Model Context Protocol. Small thing: it could search our docs and open a doc by name. A teammate, being a teammate, pasted this into the chat pretending to…...

dzone.com
dzone.com > articles > ai-agentic-promise-peril-predictability

AI and Agentic: Promise, Peril, and Predictability

1+ day, 6+ hour ago   (596+ words) Some filmmakers have this uncanny ability to see what's coming before the rest of us do. Eagle Eye (2008) was one of those films. In it, a government hijacked by an AI platform experienced chaos across an entire system. Then there…...

dzone.com
dzone.com > articles > hardening-mcp-gateways

Mitigating July 28 Security Risks in Java Applications

3+ day, 3+ hour ago   (641+ words) The upcoming release of the July 28 Model Context Protocol (MCP) specification is a massive milestone for AI integration. By shedding the baggage of stateful connections and embracing a streamlined, stateless HTTP paradigm, MCP has finally become enterprise-ready. Developers can now…...

dzone.com
dzone.com > articles > ai-agent-search

Search Is Becoming the Control Plane for AI Agents

3+ day, 8+ hour ago   (944+ words) Your agent won't be able to discover tools in 5 years using hardcoded API integrations. It will look for the capability that it requires, read the description of the tool, and call it at runtime. That change alters the integration model…...

dzone.com
dzone.com > articles > security-platform-property

Security Is a Platform Property, Not a Pipeline Step

4+ day, 6+ hour ago   (676+ words) But I missed an important line in the azurerm backend config. If use_azuread_auth = true is not explicitly set, the provider uses key-based authentication by default. Since key authentication had been disabled, terraform init failed and the pipeline broke. The actual fix…...

dzone.com
dzone.com > articles > soc-wrong-question

Every SOC Today Is Answering the Wrong Question

1+ week, 5+ hour ago   (1099+ words) Ask most detection engineers what a SOC does, and they'll say: it finds compromised machines. That distinction — timeline versus graph — is the entire argument of this piece. I'm going to call the architecture that follows from it a Continuous Evidence…...

dzone.com
dzone.com > articles > factor-secure-cloud-apps

12 Factor Framework for Secure and Compliant Cloud Apps

1+ week, 3+ day ago   (666+ words) It began with a late-night alert. A critical cloud application, serving thousands of users, had just been flagged for a security violation. No “hack” had occurred; nothing obviously was broken. What appeared to be a minor misconfiguration had quietly exposed…...

dzone.com
dzone.com > articles > zero-trust-foundry-agents

Zero-Trust Networking for Microsoft Foundry Agents

1+ week, 4+ day ago   (20+ words) Secure Microsoft Foundry agents with zero-trust networking, managed identities, RBAC, private networking, and least-privilege access for enterprise AI....

dzone.com
dzone.com > articles > machine-identity-debt

Machine Identity Debt and Cloud Security

1+ week, 4+ day ago   (1257+ words) Cloud-native systems now create far more machine identities than human ones. Security strategies built around workforce identity are no longer sufficient. Here's what engineering leaders should build instead. That's the detail worth sitting with. Every access control that companies had…...

dzone.com
dzone.com > articles > goodbye-skeleton-keys-why-machine-identity-broke-i

Goodbye, Skeleton Keys: Why Machine Identity Broke IAM

1+ week, 4+ day ago   (1272+ words) Cloudflare published its own forensic timeline of the Salesloft Drift breach down to the minute, and it's worth sitting with the detail for a second. At 11:51 on August 9, 2025, an actor researchers track as GRUB1 tried to validate a stolen Cloudflare API…...