<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Access-Control on CuraSec</title><link>https://curasec.metacog.co.kr/tags/access-control/</link><description>Recent content in Access-Control on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 12:43:46 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/access-control/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Agent Security Requires Enforcement Beyond Visibility</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-seeing-ai-agents-is-not-enough-security-teams-must-enforce-w/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-seeing-ai-agents-is-not-enough-security-teams-must-enforce-w/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Useful framing on the gap between observing AI agent behavior and actually constraining it via identity-layer controls and least privilege — worth tracking as agent deployments grow, but no specific system change is indicated today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization is deploying AI agents, use this as a prompt to establish an access-control and least-privilege policy for agent identities before adoption outpaces governance — add to the AI security roadmap this quarter.&lt;/li>
&lt;/ul></description></item><item><title>RabbitMQ Flaws Could Leak OAuth Secrets, Break Tenant Isolation</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> RabbitMQ is widely deployed as enterprise messaging infrastructure; these access control flaws — OAuth client secret leakage and cross-tenant queue metadata exposure — represent real risk for teams running it in multi-tenant or OAuth-integrated configurations. No active exploitation or PoC reported, but identify affected versions and schedule patching once a fix is available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no reported exploitation, and no actionable detection surface in this disclosure; file for context in case RabbitMQ compromise indicators surface later, but no hunt or detection work is warranted now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Essay: Frontier AI access may soon be constrained by economics and security</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-access-to-frontier-ai-will-soon-be-limited-by-economic-and-s/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-access-to-frontier-ai-will-soon-be-limited-by-economic-and-s/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Opinion piece on emerging constraints around frontier AI access; useful background for shaping internal AI usage policy before regulatory or economic forces make decisions for you.&lt;/li>
&lt;/ul></description></item><item><title>SFDS: SD-JWT-Based Architecture for IAM-Free File Sharing</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-sfds-selective-file-disclosure-system/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-sfds-selective-file-disclosure-system/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic proposal to embed cryptographic authenticity directly into shared files using SD-JWT, bypassing centralized IAM. Worth evaluating if you distribute immutable resources (PDFs, configs) and want to reduce identity-infrastructure dependencies, but no running system changes needed today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Deno releases Claw Patrol: agent firewall for production system access</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-show-hn-claw-patrol-a-security-firewall-for-agents/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-show-hn-claw-patrol-a-security-firewall-for-agents/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> If you&amp;rsquo;re wiring AI agents to production systems (Postgres, K8s, GCP), Claw Patrol is a concrete architecture reference for protocol-aware access control and human-approval gates — worth evaluating this quarter before expanding agent permissions.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates the emerging pattern of autonomous agents needing access to production systems and the governance gap that creates — relevant input for drafting an AI agent access policy before adoption outpaces controls.&lt;/li>
&lt;/ul></description></item></channel></rss>