P0 Security partners with Zscaler to advance Zero Trust for private resources.

AI agents

The identity risks of vibe coding

6 mins

The identity risks of vibe coding

Vibe coding changes the relationship between a developer and the code they ship. It does not change the fact that code carries identity and access decisions, and that those decisions have consequences.
Claude didn’t go rogue. Permissions did.

5 mins

Claude didn’t go rogue. Permissions did.

The PocketOS incident is being told as a story about a coding agent that went off the rails, but that is not the true extent of the tale. It is a story about a long-lived API token with no scoping, no expiry, no approval gate, and no separation between production and backup, sitting where any sufficiently curious actor could find it.
No results found.