SE Radio 733: Max Corbridge on Securing AI Agents

SE Radio 733: Max Corbridge on Securing AI Agents

Max Corbridge, an ethical hacker and red teamer who is co-founder and CEO of Secure Agentics, speaks with SE Radio host Amey Ambade about how AI agents get attacked and what engineers can actually do to defend them. Drawing on years of offensive security work, Corbridge frames agents as a new and largely undefended attack surface: the industry has handed AI systems autonomy and the ability to act in the real world while carrying forward prompt injection, a flaw the frontier labs themselves describe as effectively unsolvable. He likens the moment to the early, lawless days of the web, when SQL injection was everywhere and adoption ran far ahead of security.

The conversation builds from first principles as Corbridge explains what separates an agent from ordinary software and why three properties make them hard to secure: they are non-deterministic, their language-model core can be coerced, and they are increasingly interconnected through MCP servers, other agents, databases, and email. Turning to the attack surface, Corbridge lays out his "lethal trifecta" (a vulnerable core, dense interconnection, and security tooling that has not caught up) and contrasts the decades of layered defenses protecting an ordinary email inbox with the thin protection around agents that take autonomous actions on critical systems.

The heart of the episode is defense. Corbridge orders practices by leverage: least-privilege access and privilege separation, sandboxing where feasible, imperfect-but-useful guardrails as one layer of defense in depth, and human-in-the-loop for irreversible actions (which he notes is contentious and does not scale). The discussion closes on detecting a compromised or drifting agent, the value of watching an agent's chain-of-thought reasoning alongside its actions, the open-source tooling landscape (including Corbridge's own project, Adrian), and his central advice: build security in proactively, define what good agent behavior looks like up front, and avoid bolting it on after agents have already spread across the business.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(739)

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

SE Radio 734: Sathiesh Veera on Engineering Data-Protection Guardrails with LLMs

Sathiesh Veera, a GenAI Solutions Architect at At&T, speaks with host Brijesh Ammanath about the data-protection guardrails required when using LLMs. The core issue is that LLMs sit outside the cloud ...

19 Aug 42min

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

SE Radio 732: Jason Gorman on The Effective Use of AI For Software Development

Jason Gorman, a software development expert and founder of Codemanship, joins host Giovanni Asproni to explore how best to use AI in software development. They start by considering how established tec...

5 Aug 57min

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

SE Radio 731: Sonali Varde on AI and the Engineering Manager Role

Sonali Varde, Senior Software Engineering Manager at LinkedIn, joins host Kanchan Shringi to discuss how AI is changing the role of the engineering manager. They explore how AI is showing up in day-to...

29 Juli 50min

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

SE Radio 730: Birgitta Boeckeler on Harness Engineering for AI Agents

Birgitta Boeckeler, a Distinguished Engineer and consultant focused on AI-assisted software delivery at Thoughtworks, joins host Priyanka Raghavan for a deep dive into harnesses for AI agents. The epi...

22 Juli 54min

SE Radio 729: Garth Mollett on AI Supply Chain Security

SE Radio 729: Garth Mollett on AI Supply Chain Security

Garth Mollet, Senior Principal Product Security Engineer and Technical Advisor for Product Security at Red Hat, joins host Robert Blumen for a discussion of AI supply chain security. They start with t...

15 Juli 48min

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

SE Radio 728: Clare Liguori on AWS Strands SDK for AI Agents

Clare Liguori, a Senior Principal Engineer who works on developer tooling and agentic AI at Amazon Web Services, speaks with host Sri Panyam about the Amazon Strands Agents SDK. This episode explores ...

8 Juli 1h 8min

SE Radio 727: Jeroen Janssens and Thijs Nieuwdorp on Using Polars

SE Radio 727: Jeroen Janssens and Thijs Nieuwdorp on Using Polars

Jeroen Janssens, Head of Developer Relations at Posit, and Thijs Nieuwdorp, a developer relations engineer at Polars, speak with host Gregory M. Kapfhammer about Polars, a Python package for transform...

2 Juli 1h 2min

Populärt inom Utbildning

det-skaver
historiepodden-se
rss-bara-en-till-om-beroende-medberoende
harrisons-dramatiska-historia
nu-blir-det-historia
rss-viktmedicinpodden
allt-du-velat-veta
johannes-hansen-podcast
roda-vita-rosen
not-fanny-anymore
rikatillsammans-om-privatekonomi-rikedom-i-livet
i-vantan-pa-katastrofen
rss-max-tant-med-max-villman
sektledare
rss-basta-livet
rss-traningsklubben
sa-in-i-sjalen
rss-foraldramotet-bring-lagercrantz
rss-okrystat
kan-jag-sa-kan-du-podden