A conference recap from ConFoo 2026 in Montreal, centered on the theme of guardrails for fast-moving AI and software systems. Key sessions covered: applying Zero Trust and Identity Aware Proxies to agentic AI access (MCP servers, non-human identities); treating prompts like adversarial inputs with canary tokens and CI/CD-based evaluation; .NET/NuGet supply chain attacks exploiting legitimate extension points like module initializers and source generators; and OWASP Top Ten 2025 as a mirror for systemic control failures. Overarching takeaways: enforce per-request trust over perimeter trust, treat dependency updates as privileged operations, and build observable controls that survive environmental drift.

11m read timeFrom blog.gitguardian.com
Post cover image
Table of contents
The Wristband Check for Your BotsPrompt Hygiene Is the New Input ValidationNuGet as a Delivery Truck With a False BottomOWASP as a Mirror, Not a ChecklistBuild for AI Speed With Control As A Requirement

Sort: