<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cyron Blog</title><description>Practical guides, threat analysis, and release notes from the Cyron team.</description><link>https://cyron.io/</link><language>en-gb</language><item><title>Introducing Cyron AI Security: agent boundary protection for MCP and A2A</title><link>https://cyron.io/blog/introducing-cyron-ai-security/</link><guid isPermaLink="true">https://cyron.io/blog/introducing-cyron-ai-security/</guid><description>Cyron AI Security inspects what AI agents send to tools and to other agents, blocks the threat classes you choose and runs fully air-gapped on-premise.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Agent security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>One sensor, two engines: how Cyron closes the loop on AI-agent attacks</title><link>https://cyron.io/blog/one-sensor-two-engines/</link><guid isPermaLink="true">https://cyron.io/blog/one-sensor-two-engines/</guid><description>How Cyron On-Premise handles an attack on an AI agent: the kernel sensor captures it, Cyron AI Security judges it, and the sensor blocks the source.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>On-premise</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>What is new in Cyron, September 2026</title><link>https://cyron.io/blog/september-2026-release/</link><guid isPermaLink="true">https://cyron.io/blog/september-2026-release/</guid><description>Cyron AI Security arrives, MCP and A2A traffic is recognised in every edition, and attacks on WebSocket, gRPC and streams now trigger a block.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Release</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>Tool poisoning, explained: how a tool description can hijack your agent</title><link>https://cyron.io/blog/tool-poisoning-explained/</link><guid isPermaLink="true">https://cyron.io/blog/tool-poisoning-explained/</guid><description>A tool description can hijack your AI agent. See where poisoned instructions hide, why gateways and firewalls miss them and what to check today.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><category>Agent security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>Why WAFs Miss WebSocket Attacks, and How to Detect Them</title><link>https://cyron.io/blog/websocket-security-attacks-waf-bypass/</link><guid isPermaLink="true">https://cyron.io/blog/websocket-security-attacks-waf-bypass/</guid><description>Many WAFs stop reading at the WebSocket handshake. See the attacks that slip past, how to detect them in live frames, and a six-point test checklist.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>API security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>Cyron March 2026 Release: Streaming and RPC Protection</title><link>https://cyron.io/blog/march-2026-release/</link><guid isPermaLink="true">https://cyron.io/blog/march-2026-release/</guid><description>Cyron&apos;s March 2026 release brought streaming and RPC protection to the platform. Read what shipped, then follow every later release in the Cyron changelog.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate><category>Release</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>Send API Security Alerts to Your SIEM by Webhook</title><link>https://cyron.io/blog/api-security-siem-integration/</link><guid isPermaLink="true">https://cyron.io/blog/api-security-siem-integration/</guid><description>Send signed, OCSF-aligned API security events to any SIEM that accepts a webhook. See a sample event, the fields that matter and how to set it up today.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>Guide</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>API Security for Startups: First Steps and What It Costs</title><link>https://cyron.io/blog/api-security-startups-budget-guide/</link><guid isPermaLink="true">https://cyron.io/blog/api-security-startups-budget-guide/</guid><description>A 30-day API security plan for startups, with a cost table of free tools and published prices. Start with what is free and add cover as you grow.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>Guide</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>BOLA vs BFLA vs IDOR: API Authorization Attacks Explained</title><link>https://cyron.io/blog/bola-vs-bfla-api-authorization-attacks/</link><guid isPermaLink="true">https://cyron.io/blog/bola-vs-bfla-api-authorization-attacks/</guid><description>BOLA, BFLA and IDOR compared: what each attack targets, the signals that reveal it in live API traffic, and how to test your own endpoints today.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>API security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>Credential Stuffing on APIs: Detection Signals That Work</title><link>https://cyron.io/blog/credential-stuffing-detection-prevention/</link><guid isPermaLink="true">https://cyron.io/blog/credential-stuffing-detection-prevention/</guid><description>Credential stuffing looks like ordinary failed logins across many accounts. Learn the detection signals that separate it from spraying and brute force.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>API security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>How to Detect SQL Injection in API Traffic</title><link>https://cyron.io/blog/detect-sql-injection-api-traffic/</link><guid isPermaLink="true">https://cyron.io/blog/detect-sql-injection-api-traffic/</guid><description>Where SQL injection hides in API requests, the five variants Cyron recognises and why context checks keep alerts clean. Includes one worked request.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>API security</category><author>office@cyron.io (Shreyans Bhatt)</author></item><item><title>OWASP API Security Top 10 (2023): A Practical Checklist</title><link>https://cyron.io/blog/owasp-api-security-top-10-2023/</link><guid isPermaLink="true">https://cyron.io/blog/owasp-api-security-top-10-2023/</guid><description>The OWASP API Security Top 10 (2023) as a working checklist: each risk, how to test for it, and what Cyron detects in all ten categories. Use it today.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>API security</category><author>office@cyron.io (Shreyans Bhatt)</author></item></channel></rss>