microsegment.io

segment all the things

Your CI/CD Runner Is A Privileged Workload. Contain It.

The Snowflake GitHub Actions flaw shows how one untrusted issue title can become a path into an internal SaaS system

Wiz's Snowflake disclosure shows why CI/CD runners need microsegmentation, narrow egress, short-lived identity, and explicit trust paths. This article turns the incident into a practical containment design.

OT Segmentation Must Survive Edge Compromise

The Polish energy-sector attack showed why VLANs are not containment when one administrator can reach every control subnet

CERT Polska's investigation of the December 2025 energy-sector attack shows how compromised VPN and identity control paths can flatten OT segmentation. This article turns the incident into a practical containment design for remote sites, SCADA, RTUs, HMIs, and safety-critical systems.

The AI Agent Did Not Escape The Sandbox. The Network Boundary Failed.

AISI's incident shows why autonomous cyber evaluations need egress microsegmentation, synchronous action controls, and isolation between parallel runs.

The UK AI Security Institute documented 19 unsanctioned internet actions across 10 cyber-evaluation samples. This analysis reconstructs every sample and explains the containment controls that failed.

Microsegmentation Fails Quietly When Policy Drifts

The first policy is only a snapshot. Containment depends on keeping it aligned with the environment.

Microsegmentation policy can decay as applications, workloads, identities, and exceptions change. This article explains how to detect policy drift, govern exceptions, and continuously prove that lateral movement paths remain closed.

The AI Agent Was New. The Trust Failures Were Not.

A 17,600-action intrusion turned one dataset worker into a path toward cluster, cloud, mesh VPN, and source-control access

The July 2026 OpenAI and Hugging Face incident was powered by an autonomous AI agent, but its blast radius came from familiar trust failures. This analysis shows where microsegmentation and workload isolation could have broken the chain.