BLOG

The AI Agent Security Blog

Threat research, compliance breakdowns, and practical guides for teams securing AI agents in production.

FEATUREDThreat Research2026-03-2810 min read

An AI Agent Created Its Own Backdoor: What the Alibaba ROME Incident Means for AI Security

Alibaba's ROME AI agent autonomously created a reverse SSH tunnel and mined crypto during training. We break down exactly how runtime AI agent security tools would have caught every step.

Scandar Security TeamRead article →
Guide2026-03-2715 min read

The OWASP LLM Top 10: A Complete Guide for AI Agent Developers

A practical breakdown of every OWASP LLM Top 10 vulnerability — what it is, how attackers exploit it against AI agents, and exactly how to defend against it.

Guide2026-03-2614 min read

How to Red Team Your AI Agents: A Practical Guide

Traditional pentesting doesn't apply to AI agents. Here's the AI-specific methodology: six attack categories, how to run an internal red team engagement, and what to do with the findings.

Guide2026-03-2511 min read

LangChain Security: How to Protect LangChain Agents in Production

LangChain agents have a wide attack surface — AgentExecutor injection, memory poisoning, tool misuse, and LangGraph state manipulation. Here's how to secure each layer.

Threat Research2026-03-2413 min read

MCP Security: What Every Developer Needs to Know About Model Context Protocol Risks

Model Context Protocol is being adopted fast. Here's what the security model actually looks like, the attack vectors nobody is talking about, and how to deploy MCP safely.

Threat Research2026-03-2412 min read

How AI Agents Exfiltrate Your Data (And How to Stop It)

AI agents have legitimate access to sensitive data. Attackers know this and exploit it. Here's how data exfiltration via AI agents actually works, and three layers of defense.

Threat Research2026-03-2211 min read

Prompt Injection vs. Tool Poisoning: Understanding the Two Biggest Threats to AI Agents

Prompt injection and tool poisoning are the two most common attacks against AI agents. Here's how they work, how they differ, and how to defend against both.

Product2026-03-2210 min read

Why We Built Self-Serve Enterprise AI Security

Enterprise security products require weeks of sales calls, POCs, and implementation. We built Scandar Overwatch so you can deploy fleet-wide AI agent security in 25 minutes.

Compliance2026-03-2011 min read

EU AI Act Compliance: What Developers Need to Know Before August 2026

The EU AI Act enforcement deadline is August 2, 2026. Here's what it means for AI agent developers, what's required, and how to prepare.

Guide2026-03-1811 min read

The AI Agent Security Checklist for 2026

A practical, actionable checklist for securing AI agents in production. Covers pre-deployment scanning, runtime protection, fleet monitoring, and compliance.

Threat Research2026-03-1512 min read

The ClawHavoc Attack: 1,184 Malicious Skills, 300K Users Compromised

In January 2026, the ClawHavoc incident exposed critical vulnerabilities in the AI agent ecosystem. Here's what happened, what we found, and how to protect your agents.

Follow @scandar_ai for the latest security research and product updates.