A TrustFix explainer on CISA's KEV catalog — the authoritative, public-domain list of vulnerabilities known to be exploited in the wild — and how exploitation so often pivots through non-human identities and the credentials they hold.
NHI2 Secret LeakageNHI4 Insecure AuthenticationNHI5 Overprivileged NHI
A TrustFix explainer on the security risks introduced when AI agents call tools over the Model Context Protocol — tool poisoning, tool-description injection, indirect prompt injection, and unmediated delegation — and what is provable about each.
Agent: tool poisoningAgent: tool-description injectionAgent: indirect prompt injectionAgent: over-privileged agentAgent: unmediated delegation hop
A TrustFix explainer on the OWASP Non-Human Identity Top 10 — the emerging shared vocabulary for the risks that service accounts, tokens, and AI agents introduce. We map each category to what is provable versus assumed.
NHI1 Improper OffboardingNHI2 Secret LeakageNHI5 Overprivileged NHINHI7 Long-Lived SecretsNHI10 Human Use of NHI