2 citations · 2 across the 3 of their papers we have counts for
5 papers
Can AI Write Compliant Code, and to What Extent? Evaluating SOC 2 Compliance of Claude Fable 5, Claude Opus 4.8, and Claude Opus 5 Across Four Use Cases
Iccha Sethi, Herman Errico
Software teams now delegate production code to language models, including code that provisions storage, handles credentials, and stores regulated data, so we asked whether a model…
Demystifying the Mythos or Disrupting Bugonomics? From Zero-Day Asymmetry to Defender Remediation Throughput
Alfredo Pesoli, Herman Errico, Lorenzo Cavallaro
Recent demonstrations of large language models producing candidate and confirmed vulnerabilities in production software have renewed the narrative that AI will reshape offensive an…
Autonomous Action Runtime Management(AARM):A System Specification for Securing AI-Driven Actions at Runtime
Herman Errico
As artificial intelligence systems evolve from passive assistants into autonomous agents capable of executing consequential actions, the security boundary shifts from model outputs…
Securing the Model Context Protocol (MCP): Risks, Controls, and Governance
Herman Errico, Jiquan Ngiam, Shanita Sojan
The Model Context Protocol (MCP) replaces static, developer-controlled API integrations with more dynamic, user-driven agent systems, which also introduces new security risks. As M…
Offensive tool determination strategy R.I.D.D.L.E. + (C)
Herman Errico
Intentional threats are a major risk factor related to vulnerabilities in critical infrastructure assets, and an accurate risk assessment is necessary to analyze threats, assess vu…