Blog
Year
- 2026
Category
- Insights
- Incident
- Product
Tag
- AI agents
- Attack surface
- Non-human identity
- Zero standing privilege
- Execution control
- AI-native PAM
- Security
- Incident analysis
- PAM
- Product
- Alpacon
- Audit
The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Insights
Adding AI agents shouldn't mean adding more security exposure
Expanding your attack surface isn't the price of an AI agent. It's an artifact of how you wire it in – and it's avoidable.
Eunyoung JeongFounder & CEO · 9 July 2026

Incident
The gate worked. The database was still dumped.
Sysdig documented the first in-the-wild LLM agent intrusion: four pivots, every access gate cleared, database exfiltrated. The layer neither covers.
Eunyoung JeongFounder & CEO · 24 June 2026

Product
Work Sessions: the audit unit your CISO actually needs
Alpacon's Work Sessions turn fragmented audit timelines into one object – declared intent, approval gate, session-scoped sudo, unified record.
David CalvertDeveloper Advocate · 7 May 2026