LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day
ai

AI Agent Gateway: Open-source tool keeps credentials out of agent configs

Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model…

ZeroDay News ·

Source: Help Net Security

Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model (LLM) providers.

Traditionally, AI agents often store model keys and MCP credentials directly within their configuration files, distributed across developer laptops and continuous integration (CI) runners. This practice creates multiple points of exposure, as compromise of any single configuration file can lead to the theft of sensitive credentials. Furthermore, without a centralized control mechanism, there is no inherent check on an agent's permissions when it attempts to use a tool.

The AI Agent Gateway addresses these vulnerabilities by ensuring that agents never directly possess sensitive credentials. Instead, an agent registers the gateway as its MCP server and includes a gateway key and a profile name with each request. Upon receiving a request, the gateway first authenticates the gateway key, which is linked to a specific tenant and role. It then verifies whether the designated profile is authorized to use the requested tool. If the request is denied, an error is logged, and the call is blocked from reaching the backend. If approved, the gateway retrieves the actual credential from an encrypted store and attaches it to the outgoing request, effectively abstracting the credential from the agent.

This access control is enforced in real-time at the moment of the call, augmenting the gateway's ability to prune the list of tools an agent is even aware of. Consequently, even if an agent is manipulated into attempting to call a tool it was never shown, the gateway will still refuse the request.

The gateway also supports routing LLM traffic, allowing organizations to manage access to providers such as Anthropic (directly or via AWS Bedrock), OpenAI, and Gemini. By adjusting an SDK's base URL, model traffic can be directed through the gateway, which then records token usage and estimates costs for each call.

Tuskira highlights two default configurations that require careful attention. First, profiles are only bound to keys when explicitly configured. An unbound key allows the caller to specify any profile in a request header, meaning a leaked unbound key could grant access to any profile's permissions. Tuskira recommends binding each key to its specific profile to limit the scope of a leaked key, such as a CI key, to only what its associated profile permits. The sample CI profile provided by Tuskira allows access to only one tool.

Second, the demo stack of the gateway stores LLM request and response bodies, capped at 1 MiB each, for display in the console. These bodies can contain sensitive prompts and code sent by agents. Tuskira advises users to disable this storage setting if privacy is a concern.

The shipped Docker Compose file for the gateway permits outbound connections to the host machine and the loopback range for local testing. Tuskira instructs users to remove these exceptions in any shared or production environment. By default, the gateway otherwise blocks connections to private and loopback addresses and consistently blocks the cloud metadata address.

The AI Agent Gateway is available for free on GitHub and runs on macOS and Linux, with Windows support through WSL2 being untested. The repository includes practical examples for integration with various tools and platforms, including Claude Code, Cursor, VS Code, Codex CLI, Python agents, and Kubernetes.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing

The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.

nation-state

AI endpoint management: Visibility, compliance, and remediation

Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…

vulnerability

Automation, AI agents or people? Sorting out who handles each security finding

A recent survey of 200 senior security and technology leaders reveals significant concerns about the escalating complexity of software security programs, particularly in the wake of increased AI adoption. Over half of the respondents, primarily from companies with 10,000 or more employees, anticipate struggles in simplifying their security operations if current practices persist.

vulnerabilitycritical

Android’s October 2026 Updates Patch 25 Vulnerabilities

Android’s October 2026 security updates have addressed a total of 25 vulnerabilities across the platform. Among these, a critical flaw within Android’s System component has been highlighted, which could potentially allow for privilege escalation on affected devices. The updates are designed to enhance the overall security posture of Android devices by resolving these identified weaknesses.

vulnerabilitycritical

Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.

patchcritical

Even with OT network visibility, critical infrastructure operators struggle with legacy equipment

A recent survey of over 1,600 security and operations leaders in critical infrastructure organizations reveals that despite widespread adoption of security tools, many operators still lack full visibility into their operational technology (OT) networks and struggle with the risks posed by legacy equipment. The study, conducted by Palo Alto Networks, highlights a significant challenge in…