DevOps / SRE / Platform · 31.08.2026, 10:17 UTC
Tide launched Raziel for AI security. It assumes hackers are inside.
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | The New Stack ↗ |
| Veröffentlicht | 31.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Michael Loewy, co-founder of the Tide Foundation, says the security industry was already losing ground to hackers before AI. Everything from a typo to a state actor could create a breach.
“Before AI even came into the developer consciousness, a developer or a platform owner needed to be perfect all the time — perfectly patched, free of errors, free of bugs — and an attacker only needed to be right once to get in,” Loewy tells The New Stack. “It’s virtually impossible, which is why we’re seeing breaches in the news every day, and the biggest companies in the world getting breached. It could be one poorly written line of code, one misconfiguration, and then you’re done.”
AI has, of course, compounded the risks.
Loewy warns that vast amounts of inadequately reviewed, error-prone code are being produced just as advanced AI models are becoming highly skilled at discovering and exploiting vulnerabilities. Meanwhile, AI agents are creating software and performing sensitive, privileged actions.
Attackers gain access by getting past authentication and authorization. But what Loewy and co-founder Ben Waters are most worried about is the authority agents gain once inside.
Authority, as they define it, is the power to decide who or what can get into which system, who can access and decrypt which data, and who can authenticate, authorize and assign permissions. It lives in the systems we’re forced to unquestioningly trust in the form of admin credentials, root keys, identity providers, and service accounts. As Loewy says, “the problem is that it always lives somewhere, and someone …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info VS Code 1.135 Gives AI Coding Agents a Second Opinion
- info A Simple Website Summary Just Exposed the Limits of AI Coding Guardrails
- info Optimize EKS operations with agents: Reduce MTTR with AWS DevOps Agent and a Kubernetes Operator
- info GitHub Tightens Copilot’s Billing and Governance Rules Ahead of a Busy Fall