SShortSingh.
Back to feed

Cloud Security Alliance releases MAESTRO framework to threat-model AI agents

0
·2 views

The Cloud Security Alliance (CSA) has published MAESTRO, a structured threat-modeling framework designed specifically for agentic AI systems. Authored by Ken Huang of CSA's AI Safety work, MAESTRO stands for Multi-Agent Environment, Security, Threat, Risk, and Outcome. The framework breaks down an AI agent into seven layers — including foundation models, data operations, agent frameworks, and deployment infrastructure — allowing security teams to systematically identify vulnerabilities at each level. Unlike older methods such as STRIDE or PASTA, MAESTRO accounts for AI-specific risks like prompt injection, poisoned training data, and autonomous actions that no one explicitly scripted. CSA has also released a companion Agentic AI Red Teaming Guide that uses the same seven-layer structure to support hands-on security testing.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

React Native Developers Are the New Target: A Guide to Securing Your Own Machine

A detailed security guide highlights that React Native developers themselves—not just end users—have become the primary targets of supply chain attacks. The guide warns that routine commands like yarn install execute untrusted code with full user privileges, capable of accessing SSH keys, keychains, and environment files without any sandboxing. Configuration files such as metro.config.js, Podfile, and build.gradle are actually executable programs that run automatically on build or project open, creating silent attack surfaces. Real-world incidents like nx/s1ngularity, Shai-Hulud, and GlassWorm demonstrate that these threats are active, with one attack hiding malicious payloads in invisible Unicode characters that evaded code review entirely. The guide also flags AI agent MCP servers as an emerging risk, with over 30% found to carry exploitable vulnerabilities that have already been used to steal private SSH keys.

0
ProgrammingDEV Community ·

Hermes Agent Builds Persistent Skills to Cut Costs for Long-Running AI Tasks

Nous Research released Hermes Agent in February 2026 as an open-source MIT-licensed runtime designed to address a core weakness in AI agent frameworks: the inability to retain and reuse knowledge across sessions. Unlike conventional frameworks that discard reasoning after each task, Hermes logs decision points and tool calls, then enters a reflective phase to assess what worked and convert successful approaches into structured 'skill documents.' These documents are indexed using SQLite FTS5, allowing future similar tasks to query the skill library before invoking the model, with community benchmarks showing up to 40 percent speed gains after around 50 accumulated skills. The architecture is built on five pillars — memory, skills, a persistent behavioral config called 'Soul', scheduled cron jobs, and a self-improvement meta-layer — all designed to compound efficiency over time. Deployment options range from a $59/month managed service to self-hosted builds costing as little as $6–$9 per month, with local inference on an 8B model reportedly achieving 91 percent tool call accuracy on just 8GB of VRAM.