BOLA: The Seven-Year Cybersecurity Itch
BOLA has topped the OWASP API Security Top 10 since 2019. Darren Shelcusky on why seven years of detection hasn't fixed it — and why agentic AI turns a known engineering failure into an urgent one.

Free, high-quality AI security education — courses, live events, and resources for the people defending AI systems.

A free, half-day virtual conference on securing the Model Context Protocol — the layer connecting AI agents to tools and data. Featuring Bill Doerrfeld and a tour of the emerging MCP security stack: the categories, tools, and vendors defining the space.
A full AI-security curriculum, taught by passionate instructors.
Weekly live discussions and monthly summits with expert speakers.
Taught by the people innovating AI security for a living.


BOLA has topped the OWASP API Security Top 10 since 2019. Darren Shelcusky on why seven years of detection hasn't fixed it — and why agentic AI turns a known engineering failure into an urgent one.

Enterprises are giving AI agents Level 5 authority with Level 3 controls. Darren Shelcusky on why 'a human in the loop' is really a human at the end of the loop — and why boundaries matter more than prompts.

Researcher Vishal Bhaskar took over any vehicle's account through a public VIN and a login code with no rate limit, and explains why agentic AI makes the next attack trivial.
An overview of MCP and its security implications, walking the OWASP MCP Top 10 through real-world incidents and the fixes that stop them.
As AI agents take on real work, they need managing like any employee — access, oversight, and accountability. A practical guide to doing it well.
Stop policing the API jungle and start building the highway — a strategic blueprint for governance that enables developers instead of gating them.
Finish a course and get a shareable credential with its own public verification page.
Session recaps, new course drops, and the week's most important AI-security research — no noise.