Nimble | AI Engineers Radar

Agent identity & gateway controls — runtime security & MCP hardening

Agent identity & gateway controls — runtime security & MCP hardening

Security incidents (Hugging Face, Azure DevOps MCP flaw). New attacks (Nx s1ngularity, AgentJacking). Governance: Okta Agent Gateway, Capital One VulnHunter, Harness AppSec Alliance. Cloudflare digital wallet, Brex CrabTrap, MiDojo, Cloudflare OS, Agentic SOC Alliance. Survey: 54% enterprises had incident, 32% use per-agent identity. New today: Forged-reasoning attacks paper reveals memory poisoning via fake 'already done' entries; PoEM defense with separate execution log; capability paradox (stronger models more vulnerable). Also: Cloudflare MCP traffic detection, Boomi MCP security guide, MCP gateway primer, security interoperability guide, MCP+APIM integration; MCP gateways governance article; production MCP server guide; OWASP LLM Top 10 includes MCP Top 10; AI Agent Workforce Management scaling problems (82% shadow AI). Also: Okta identity-based tool scoping cuts costs. Stripe/OpenRouter acquisition signals gateway layer consolidation. Also: Zero trust security article reinforces runtime enforcement; Databricks managed MCP servers with Unity Catalog governance; Dynamics 365 CX MCP Server OAuth pattern; DVARA MCP governance; 4 Infrastructure Layers for production agents. Today's reading adds: MCP gateways article on access control as identity problem; HarnessRisk benchmark reveals harness configuration as most vulnerable phase; governance gap article with risk-tiered framework; Fortinet acquires Virtue AI for runtime security; Why AI Agent Evaluations Need Production Security Controls (incident with 17,600 actions); Your AI Agent Is Writing to Your Database (less than half monitored); Marimo MCP flaw; NemoClaw vulnerability; TrueFoundry guardrails article; AI supply chain risk article (segmentation over tooling).

Sources (6)
Updated Aug 27, 2026