Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “blast radius”
5 publicationsMap the OWASP Top 10 for Agentic Applications to cloud controls
Each OWASP agentic risk mapped to the controls AWS, Microsoft and Google document for their agent platforms, with a plain account of which risks no infrastructure setting can close.
AI systems · OWASP GenAI Security Project / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskDesign AI agents that contain indirect prompt injection
Filters lower the odds that an agent obeys injected text. Architecture decides what an obeying agent can reach. Compare six published patterns and CaMeL by what each removes, what it costs and what it still misses.
AI systems · Google DeepMind / AgentDojo / NIST / OWASP / Microsoft · By Cloud Security DeskGive Kubernetes pods cloud credentials without static keys
EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.
Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security DeskContain failures with cell-based architecture and shuffle sharding
Cells limit a failure to the tenants behind one partition only when routing, data and change delivery are partitioned too. Here is how to choose the key, size cells and check the shuffle-sharding arithmetic.
Resilience · AWS / Microsoft Azure / Slack · By Cloud Security DeskRun code written by AI agents inside a disposable sandbox
Treat agent-generated code as untrusted input. Pick a microVM or user-space kernel boundary, keep egress and credentials off by default, and destroy the session when the user or conversation ends.
AI systems · Amazon Web Services / Microsoft Azure / Google Cloud / Firecracker / gVisor / OWASP · By Cloud Security Desk