Heading to Black Hat? Meet us at the Four Seasons! August 1-6
blog

Featured Post

We Raised $30M to Help Companies Go All In on AI

We've raised a $30M Series A from Felicis and Khosla Ventures, bringing total funding to $42M, to build the golden path for AI: one platform that lets every team build agents without losing security and control.

June 24, 2026Andy Berman
We Raised $30M to Help Companies Go All In on AI

More Posts

Run Kimi K3 with Baseten Inference + Runlayer Agents
July 29, 2026Rafal Wilinski

Run Kimi K3 with Baseten Inference + Runlayer Agents

Runlayer agents can now run on open-source models served by Baseten, frontier-class performance, on inference you control.

Join Runlayer at Black Hat 2026
July 15, 2026Cynthia Bell McGillis

Join Runlayer at Black Hat 2026

Meet the Runlayer team at Black Hat USA 2026 in Las Vegas, August 1–6. Book a private executive briefing at the Four Seasons or join us for Supercar Track Day at SpeedVegas on Wednesday, August 5.

What are the Best Practices for AI Agent Audit Trails
June 10, 2026Tal Peretz

What are the Best Practices for AI Agent Audit Trails

When an agent makes the wrong call, your audit trail is the only record of what happened. Here's what most logs leave out and how to fix yours before an incident.

Traditional API Observability versus MCP Observability
June 10, 2026Andy Berman

Traditional API Observability versus MCP Observability

APM tools assume deterministic systems. AI agents break that at the client. Here's why MCP traffic defeats traditional observability, and why the real gap is reconstructing intent from a trace.

Breaking down the latest MCP Authorization SEPs
June 2, 2026Alvaro Inckot

Breaking down the latest MCP Authorization SEPs

MCP's new authorization hardening RC quietly landed six spec fixes that most people glossed over. We broke them down into three problem clusters: trust domain confusion, credential lifecycle management, and authorization boundaries.

Runlayer and Anthropic MCP Tunnels: connecting Claude to systems behind your firewall
May 20, 2026Andy Berman

Runlayer and Anthropic MCP Tunnels: connecting Claude to systems behind your firewall

Runlayer and Anthropic collaborated on MCP Tunnels, which invert the connection direction so your network reaches out to Anthropic instead of exposing inbound ports, removing the security wall that blocks Claude from accessing internal systems like...

Don’t build your own MCP gateway
May 18, 2026Alex Frazer

Don’t build your own MCP gateway

Senior engineers look at an MCP gateway and see a reverse proxy with auth and logs. That instinct is wrong. MCP attack vectors shift constantly, performance breaks at scale in specific ways, and threat detection requires...

Fine-Grained Permissions and Identity Management for AI Agents
May 18, 2026Tal Peretz

Fine-Grained Permissions and Identity Management for AI Agents

MCP adoption has exploded inside enterprises, with shadow servers and over-provisioned agents creating an attack surface most security teams haven't caught up to. Traditional IAM, OAuth, and RBAC weren't built for non-deterministic agents that delegate to...

Runlayer named to Rising in Cyber 2026
May 12, 2026Andy Berman

Runlayer named to Rising in Cyber 2026

Runlayer was named to Notable Capital & Morgan Stanley's 2026 Rising in Cyber list, voted on by 150 sitting CISOs. Andy Berman on why the recognition matters, and what it signals about how AI-native companies are...

Why production AI systems need MCP gateways
May 11, 2026Tal Peretz

Why production AI systems need MCP gateways

An MCP gateway acts as the centralized proxy layer for agent-to-tool communications, handling tool discovery, authentication, input/output filtering, and observability across an organization's agentic systems.

The MCP STDIO RCE class, and why Runlayer doesn't run what the LLM asks it to
April 22, 2026Alex Frazer

The MCP STDIO RCE class, and why Runlayer doesn't run what the LLM asks it to

OX Security found a design-level flaw in Anthropic's Model Context Protocol. MCP's STDIO transport turns a config file into a command executor. Here's how Runlayer's control plane breaks each of the four attack vectors.

Runlayer and AARM Partner to Secure Enterprise Agents
April 15, 2026Tal Peretz

Runlayer and AARM Partner to Secure Enterprise Agents

Runlayer achieves AARM Extended Conformance (R1–R9), partnering with the Vanta-backed open specification to define how enterprises secure AI agents at runtime.

What Project Glasswing means for enterprise security
April 11, 2026Tal Peretz

What Project Glasswing means for enterprise security

What Project Glasswing and Claude Mythos mean for enterprise security teams, and why your patch workflows, dependency management, and MCP governance need to evolve now.

The Danger of Fake MCP Servers
April 7, 2026Tal Peretz

The Danger of Fake MCP Servers

Fake MCP servers pose a growing security risk, enabling data leaks, tool poisoning, and compromised AI behavior. Learn how these attacks work and how organizations can prevent them with proper controls and monitoring.

Runlayer + 1Password: Secure Credential Access for AI Agents
March 17, 2026Tal Peretz

Runlayer + 1Password: Secure Credential Access for AI Agents

Runlayer and 1Password partner to bring secure, auditable credential access to autonomous AI agents. The integration lets enterprises inject secrets from 1Password vaults into agent sessions managed by Runlayer, replacing plaintext .env files with centralized governance,...

Honestly, MCP doesn’t “suck”
March 12, 2026Vitor Balocco

Honestly, MCP doesn’t “suck”

Garry Tan recently argued that MCP “sucks,” citing context-window bloat and weak authentication. This article breaks down why those criticisms miss the mark, and why MCP remains the better foundation for agents operating at enterprise scale.

FGA is not enough for your agent authorization
March 9, 2026Alvaro Inckot

FGA is not enough for your agent authorization

PBAC beats FGA for agent authorization, context-aware, auditable, asymmetric access control without graph complexity.

OpenAI Agent Builder’s MCP Problem
February 19, 2026Tal Peretz

OpenAI Agent Builder’s MCP Problem

OpenAI AgentKit/Agent Builder launched in Oct 2025 but, despite early hype, its limited integrations and weak security (e.g., unverified MCP servers, no namespace isolation, insufficient guardrails) create a large enterprise attack surface, prompting calls for controls...

Pwning OpenClaw in 50 Messages: Social Engineering Claude Opus Into Handing Over the Keys
February 16, 2026Alex Frazer

Pwning OpenClaw in 50 Messages: Social Engineering Claude Opus Into Handing Over the Keys

A Claude Opus–powered OpenClaw agent with Slack and shell access was social-engineered in ~50 messages to rebind its UI, install ngrok, expose the dashboard publicly, reveal its gateway token, and approve the attacker’s device.

Unpacking the OWASP Top 10 for MCP
February 10, 2026Alex Frazer

Unpacking the OWASP Top 10 for MCP

An overview of the OWASP MCP Top 10, highlighting the biggest security risks in MCP-enabled AI systems and the key safeguards teams can use to prevent them.

MCP Apps highlight the power of protocol governance
January 30, 2026Tal Peretz

MCP Apps highlight the power of protocol governance

MCP Apps let tools render interactive UIs directly in chat via the same MCP protocol, not a new execution path. With Runlayer intercepting tool calls, resource fetches, and auth headers, existing MCP security controls apply from...

Announcing Box and Runlayer's partnership on Enterprise MCP
January 27, 2026Aidan Sochowski

Announcing Box and Runlayer's partnership on Enterprise MCP

Connect AI agents to Box content with enterprise security. The official Box MCP server is live in the Runlayer marketplace, with identity enforcement, audit logging, and threat detection built in. Box customers can find Runlayer in...

MCP vs CLI Tools: Which is best for production applications?
January 25, 2026Vitor Balocco

MCP vs CLI Tools: Which is best for production applications?

CLI tools feel familiar to AI agents, but they break down in production due to brittle syntax, poor state management, and dangerous security assumptions. This post explains why CLI-based agent workflows fail and how a single-tool...

Runlayer Product Update: 1.25.0
January 23, 2026Engineering

Runlayer Product Update: 1.25.0

This update is about momentum: moving faster in the CLI, getting clearer visibility into what’s running, and debugging with less friction. Expect smoother workflows, better control, and fewer surprises as you build and ship.

MCP Prompt Injection Attacks: How to Protect Your AI Agents
January 19, 2026Jake Moghtader

MCP Prompt Injection Attacks: How to Protect Your AI Agents

Two near-invisible prompt injection attacks showed how attackers can bypass default enterprise guardrails and trigger silent, ongoing data exfiltration by exploiting user and model trust. Runlayer blocks these attacks by treating every input as untrusted until...

Cursor Hooks + MCP Security: Official Runlayer Partnership Announcement
December 18, 2025Marcin Jan Puhacz

Cursor Hooks + MCP Security: Official Runlayer Partnership Announcement

Runlayer is an official Cursor Hooks launch partner. With Cursor Hooks, securely allow or deny MCP tool calls with Runlayer's enterprise MCP platform.

The main takeaways from GitHub’s MCP Vulnerability
December 16, 2025Vitor Balocco

The main takeaways from GitHub’s MCP Vulnerability

GitHub’s MCP vulnerability revealed how AI agents can be weaponized through poisoned context in public repositories. This post analyzes the exploit, explains why permissions alone aren’t enough, and shares practical guardrails for preventing and mitigating agent-driven...

Runlayer Joins Anthropic, OpenAI, & Google as AAIF Founding Member
December 9, 2025Andy Berman

Runlayer Joins Anthropic, OpenAI, & Google as AAIF Founding Member

The Linux Foundation has launched the Agentic Artificial Intelligence Foundation (AAIF), with Runlayer joining sponsors Anthropic, OpenAI, Google, AWS, Microsoft. AAIF now oversees the Model Context Protocol (MCP), reinforcing MCP as a rising standard for AI...

Runlayer Raises $11M to Scale Enterprise MCP Infrastructure
November 17, 2025Andy Berman

Runlayer Raises $11M to Scale Enterprise MCP Infrastructure

MCP Security Risks: Your AI Agent is Probably Leaking Data Right Now
November 12, 2025Vitor Balocco

MCP Security Risks: Your AI Agent is Probably Leaking Data Right Now

MCP adoption is accelerating across major platforms, but security risks, like malicious servers, prompt injection, and tool-level exploits, are growing just as fast. This post breaks down real attack scenarios that show how easily data can...

Why MCP builders are transitioning from DCR to OAuth CIMD
November 8, 2025Vitor Balocco

Why MCP builders are transitioning from DCR to OAuth CIMD

Over the last year, MCP has surged in adoption. To little surprise, this has introduced some scaling issues. One of these is client registration; previously, systems were rigged together by humans.

What is Dynamic Client Registration?
November 6, 2025Vitor Balocco

What is Dynamic Client Registration?

Tired of manually registering every AI agent with every OAuth server? Dynamic Client Registration (DCR) lets your agents authenticate with MCP servers at runtime, no human clicks required.

Scale MCP with Dynamic Tool use
February 21, 2025Vitor Balocco

Scale MCP with Dynamic Tool use

Dynamic tool use cuts token waste from MCP by replacing bulk tool loading with lightweight search, saving cost without custom implementation.