OWASP Guide to Securing Agentic AI Applications: Best Practices for Trustworthy and Secure AI Systems

August 4, 2025 Lothar Schulz 0

Discover how architectural choices can be a defense in securing agentic AI systems. This comprehensive guide explores OWASP’s latest “Securing Agentic Applications” paper, covering everything from Sequential and Hierarchical architectures to the 15 critical threat categories facing autonomous AI applications. Learn practical implementation strategies, universal security principles, and how to build trust into your agentic AI systems from the ground up.

Let the Agents Vibe: Introducing Flow Coding

July 7, 2025 Lothar Schulz 0

Introducing “flow coding”—a new multi-agent development approach where you orchestrate AI agents to collaborate on software projects. Unlike vibe coding’s human-AI partnership, flow coding enables AI-to-AI collaboration while you guide the creative process from above.

Skip the Code: How AI Prompts Now Handle Tech Due Diligence Better Than Custom Scripts

June 15, 2025 Lothar Schulz 6

I built a Python solution in January for AI-powered supplier due diligence that required Jupyter notebooks and custom code. Now I’ve discovered something game-changing: modern AI systems like like Claude, ChatGPT, and Perplexity can handle complex tech assessments through simple prompts with zero technical setup. This post reveals the comprehensive prompt framework that delivers professional due diligence results without any coding, making AI-powered supplier assessments accessible to any CISO team.

Claude 4’s 25% Syntax Error Reduction

May 26, 2025 Lothar Schulz 0

Claude 4’s release brings significant improvements to AI-assisted coding that matter for security-conscious engineers. The coding platform Lovable reports a 25% reduction in syntax errors and 40% speed improvement in production environments.
While this doesn’t directly address semantic security issues like dependency confusion attacks, fewer syntax errors allow security reviewers to focus on logic and security issues rather than basic correctness, creating opportunities for more targeted security review.