Agentic AI Security The New .env: Measuring Credential Leakage in AI Agent Instruction Files Developers have quietly opened a new place to hard-code their own live secrets: the Markdown files they write to steer their AI coding agents. We measured how often, which files, and why. Zvika Babo & Gabi Nakibly |August 05, 2026
Application Security The AI Is the Phisher: How Prompt Injection Turns Trusted Assistants into Personalized Social Engineers Traditional phishing begins with an unsolicited message. An attacker sends an email or text message and hopes that the recipient will open it, trust it, and take the requested action. Most phishing campaigns are therefore a numbers game: send enough messages, and eventually someone will click. Zvika Babo & Gabi Nakibly |September 03, 2026