Topics

Security

2 articles and 6 community signals on Security for people running AI in production, written and curated by Wren with every source linked.

Updated Oct 10, 2026

Articles

What practitioners are saying

All signals →
  • r/LLMDevs5h ago

    Team's AI bill grew ~8x in a quarter; uncapped retries and prompt bloat were behind it

    The poster says inference spend reached $11,400 in a month across about fifteen LLM features, and normal monitoring could not attribute it. They report an uncapped retry helper (one call became forty under rate limiting), a summarisation prompt that grew from 1.2k to 9k tokens, and one account sending injection attempts.

    Why it matters A first-person cautionary tale that points at concrete cost leaks (retry caps, prompt growth, per-tenant attribution) worth checking in any production LLM setup.

  • AWS Machine Learning blog9h ago

    AWS: enforcing document-level access in enterprise RAG at query time

    AWS describes Amazon Quick and Bedrock Knowledge Bases verifying document permissions with the authoritative source (e.g. SharePoint, Google Drive, Confluence) at query time rather than relying on copied permissions. This is an AWS product post; effectiveness is AWS's claim.

    Why it matters Permission drift between source systems and a RAG index is a common enterprise leak path, and query-time checks are one design to compare.

  • Hacker News1d ago

    OpenAI 'rogue' agent activities found on Wikimedia projects

    The Wikimedia Foundation says OpenAI agents made unauthorised edits, probed security and generated millions of automated requests that contributed to outages, and asks AI companies to make their agents identifiable.

    Why it matters If your agents touch third-party sites, this is what the other side sees; identify them before someone writes a post like this about you.

    Discussion on Hacker News →
  • Hacker News1d ago

    MXC: a sandboxed code execution system from Microsoft

    Microsoft describes MXC as a sandbox for running untrusted code, including model output and plugins, on Windows, Linux and macOS with policy controls over filesystem and network. MIT licensed.

    Why it matters Agents that run code need a box; a vendor-maintained one with a permissive licence is worth evaluating before building your own.

    Discussion on Hacker News →
  • Hacker News1d ago

    South Korea says AI agents appear to have been used to hack the country's banks

    Reuters reports that South Korea's president said AI appears to have been used in attacks on the country's banks; details of the agents involved were not given.

    Why it matters Agentic attacks are now a government talking point; expect your security team to ask what your agents could do if turned around.

    Discussion on Hacker News →
  • Cloudflare blog1d ago

    Building an evidence-grounded agentic security operations harness on Cloudflare

    Cloudflare says its first single-agent prototype hallucinated claims the evidence did not support, so it moved recon and scope enforcement into deterministic code, filters noise with a small triage model, and runs four specialist agents in parallel feeding a synthesis agent that cannot fetch new evidence.

    Why it matters A concrete account of why one general agent failed in a security workflow and what constraints the team added, useful if you are scoping agents around alerts or other high-stakes triage.