BlueRock Blog

Product announcements, how‑tos, and commentary on agentic security.

Product announcements, how‑tos, and commentary on agentic security.

BlueRock Blog

Product announcements, how‑tos, and commentary on agentic security.

Mar 5, 2026

The Shift from Build-Time Logic to Runtime Execution

AI agents generate execution paths at runtime. This creates new challenges for tracing, governance, and operational control across agentic tools and MCP servers.

Read More

Feb 26, 2026

Why Observability Matters for Agentic Systems

Agents make decisions, select tools, and take actions at runtime. Traditional monitoring can't trace that chain. Here's what observability needs to look like when software makes its own decisions.

Read More

Feb 19, 2026

The AI Agent Didn't Go Rogue. It Executed Within Policy.

When AI agent incidents happen, gateway logs show no violations. The failure emerges during execution — in the Agentic Execution Gap where neither security nor developers have visibility.

Read More

Feb 18, 2026

CVE-2025-68472: Inside MindsDB's File Upload Path Traversal

A path-joining miscalculation in MindsDB's file ingestion API allows attackers to read and remove arbitrary files. Learn how BlueRock's Agentic Observability Platform neutralizes this attack at the moment of file access through runtime protections BR-70 and BR-91.

Read More

Feb 17, 2026

The Agentic Observability Sandbox Now Comes to You for Free

BlueRock introduces free managed PaaS for the Agentic Observability Sandbox — full MCP visibility, process isolation, secure runtime, and FastMCP pre-deployed. Register and build.

Read More

Feb 10, 2026

The Technical Limits of MCP Gateways for Agentic AI

MCP gateways can address some security and visibility concerns in agentic AI workflows, but they also introduce non-trivial technical and operational challenges. Latency, scale, certificate management, availability, and new attack surfaces all become part of the system once a gateway is placed in the execution path. In this post, we examine the limitations of MCP gateways from an engineering and operations standpoint, based on how these systems behave at scale in real deployments.

Read More

Feb 9, 2026

Introducing Private Repo Scanning for MCP Servers to Help Build Secure-by-Default MCP Servers

As MCP servers rapidly become core execution infrastructure for AI agents, security gaps are emerging faster than teams can spot them. Private Repo Scanning gives builders early, actionable visibility into MCP risks—before agents act in production—without slowing development.

Read More

Feb 7, 2026

From Agent Demos to Autonomous Systems: The Execution Gap Enterprises Aren’t Ready For

56% of enterprises already run AI agents in production, but most aren’t ready to operate them as autonomous systems. As MCP accelerates agent adoption, execution visibility and control become the missing link.

Read More

Feb 6, 2026

Top 5 Reasons Agentic Developers Will Work Around Your MCP Gateway — Especially for AI Agents

AI agents don’t just make requests — they execute actions. This post breaks down the top reasons agentic developers inevitably work around MCP gateways, not out of recklessness, but to recover visibility, speed, and debuggability. It explains why gateway controls fail at the execution layer, how that creates real security blind spots, and why governing agent behavior requires visibility beyond the request boundary.

Read More

Feb 2, 2026

Why MCP Gateways Can’t Secure Agentic AI — And What Organizations Must Do Instead

MCP Gateways can approve requests, but they can’t govern autonomous decisions. As AI agents execute multi-step actions across systems, failures emerge during runtime — far beyond what traditional controls can see or stop. This blog breaks down why gateway security fails for agentic AI and outlines the execution-first model organizations need instead.

Read More

Jan 20, 2026

MCP fURI: BlueRock Discovers an MCP Security Gap That Enables Account Takeover of Cloud Infrastructure

Dubbed MCP fURI, this finding enables arbitrary calling of URI resources via Microsoft’s Markitdown MCP server. These unbounded URI calls can leave organizations exposed to privilege escalation, SSRF (Server-Side Request Forgery) and data leakage attacks including a full takeover of an organization’s cloud infrastructure.

Read More

Jan 13, 2026

How to Choose the Right MCP Server for Safe, Fast Agentic Development

Choosing the right MCP server isn’t about hype — it’s about shipping agents that actually work, fail safely, and scale responsibly. This guide shows developers how to evaluate MCPs for real-world reliability, security, and velocity.

Read More

Dec 3, 2025

BlueRock Unveils the Agentic Protection Platform

BlueRock is launching the Agentic Protection Platform—the first built-in runtime approach to see and secure agentic actions before they execute. As agents and MCP servers move into production with increasing autonomy, BlueRock delivers the missing foundation: visibility, trusted MCP intelligence, sandboxing, and pre-execution guardrails.

Read More

Nov 13, 2025

From Talk to Action: The Fastest, Most Secure Way to Build MCP Servers on AWS Marketplace for Free

BlueRock’s Secure MCP Server is now available on AWS Marketplace for free. The Amazon Machine Image (AMI) is built on top of Amazon Linux 2023, with FastMCP and BlueRock built-into the distribution.

Read More

Nov 12, 2025

CVE-2025-61765: BlueRock Discovers Critical RCE in Socket.IO Ecosystem

This vulnerability, CVE-2025-61765, affects multi-server deployments using common message brokers like Redis, Kafka, or RabbitMQ.

Read More

Oct 21, 2025

Securing Both Known and Unknown Vulnerabilities, with Chainguard + BlueRock

Chainguard and BlueRock solutions together enable defense-in-depth with lower friction for developers. 

Read More

Sep 9, 2025

BlueRock Delivers Runtime Reachability Intelligence (RRIQ) That Saves Developers Time

BlueRock RRIQ Is Now Available On AWS Marketplace For Amazon Linux 2023

Read More

Stay ahead of agentic threats
Get brief, technical updates when we publish new threat research, MCP registry findings, and agentic exploit breakdowns.