Your vulnerability remediation SLA starts a clock on every alert. On Redash, an open-source dashboarding tool we'll use as an example, that is 272 clocks. But only about 10% of them need action.
k9 Security Blog
Secure your cloud infrastructure quickly and confidently
EPSS vs KEV: the 2% score on a ransomware CVE
On August 25 our weekly triage deferred a Starlette alert with a 2% EPSS score. On September 1 the same alert, same code, same 2% score, was the only advisory in a 127-alert backlog that had to be fixed that day. Nothing about the vulnerability changed in that week....
Why coding agents need help triaging dependency alerts
“Why not just prompt Claude Code or Copilot to triage dependency alerts per our security policy?” is the right question. A coding agent can read your code, trace a call path, and reason about whether a vulnerable function is reachable. That is the hardest part of alert...
How to Prioritize CVEs by Risk, Not Severity
In 24 hours we scored the same CVE three times against three different projects, and it came back DEFER on one and SCHEDULE on the other two. Every call was right. The scanner’s severity label read “high” all three times. What changed was the asset context, and with it...
Your MCP server on AgentCore Runtime fails its health check at `/mcp/`. Here’s how to fix it.
We deployed the k9 MCP server to AWS Bedrock AgentCore Runtime. Tool calls worked for the first few minutes of every session, then started failing with MCP error -32010: Runtime health check failed or timed out. Local tests stayed green throughout. The fix is one small...
Severity is no longer a triage input. Risk scoring you own is.
“I’m sorry, Dave. I’m afraid I can’t do that.” NIST said it more politely on April 15. The NVD change is permanent, not a temporary glitch. CVE volume has outpaced NIST’s analysis capacity. For 25 years, vulnerability-management programs assumed the National...
Generate least-privilege EventBridge policies and restrict access to your AWS Organization with k9-cdk
Cross-account event buses are one of the most powerful integration patterns in AWS, and an easy place to make an access policy mistake. A single overly permissive Allow statement can let principals from outside your organization publish events to your bus. With k9-cdk...
Building Evals for an AI Agent: From Zero to Consistency Testing
We’re building an AI agent that triages cloud security findings. It reads a finding from AWS Security Hub or Prowler, assesses the risk, and tells an engineer exactly what to do about it with specific AWS CLI commands they can run. The agent worked. We had 620 unit...
How to Connect Strands Agents to AWS MCP with IAM Authentication
We’re building a cloud security agent with Strands Agents that triages AWS security findings. The agent uses the AWS Knowledge MCP server to search and read AWS documentation. The agent looks up remediation guides, CLI syntax, and best practices as part of its...
The top AWS Identity and Organization security launches of 2025
The AWS Identity and Organization teams launched some big improvements to IAM in 2025. Read on for a quick introduction to the six changes we think are most likely to help you make an impact securing your AWS organization and identities: Enforce MFA for root users...
