k9 Security
  • Use Cases
    • DevOps
    • Enterprise Security
    • MDR & SOC
    • OEM Integrations
  • Demo
  • Pricing
  • Docs
  • Contact
  • About
  • Blog
  • Sign up
Select Page

How to Prioritize CVEs by Risk, Not Severity

by Stephen Kuenzli | Jul 20, 2026 | AI, Development, Security

In 24 hours we scored the same CVE three times against three different projects, and it came back DEFER on one and SCHEDULE on the other two. Every call was right. The scanner’s severity label read “high” all three times. What changed was the asset...

Severity is no longer a triage input. Risk scoring you own is.

by Stephen Kuenzli | May 9, 2026 | Security

“I’m sorry, Dave. I’m afraid I can’t do that.” NIST said it more politely on April 15. The NVD change is permanent, not a temporary glitch. CVE volume has outpaced NIST’s analysis capacity. For 25 years, vulnerability-management...

Building Evals for an AI Agent: From Zero to Consistency Testing

by Stephen Kuenzli | Apr 2, 2026 | AI, Security

We’re building an AI agent that triages cloud security findings. It reads a finding from AWS Security Hub or Prowler, assesses the risk, and tells an engineer exactly what to do about it with specific AWS CLI commands they can run. The agent worked. We had 620...

The top AWS Identity and Organization security launches of 2025

by Stephen Kuenzli | Dec 16, 2025 | Security

The AWS Identity and Organization teams launched some big improvements to IAM in 2025. Read on for a quick introduction to the six changes we think are most likely to help you make an impact securing your AWS organization and identities: Enforce MFA for root users...

Export Findings from Security Hub in OCSF Format: A Complete Guide

by Stephen Kuenzli | Oct 1, 2025 | Security

Security teams have long been challenged by security findings scattered across many tools in proprietary formats that don’t play well together. If you’re managing AWS Security Hub findings and need to analyze them alongside data from other security tools,...

k9 Security launches initial support for automated IAM security review with findings in OCSF format

by Chase Christy | Aug 22, 2025 | Announcements, Security

k9 Security now automates two critical IAM security review processes and produces high-signal findings in Open Cybersecurity Schema Framework (OCSF) format. This new capability significantly enhances your ability to identify and address critical IAM security risks in...
« Older Entries

Recent Posts

  • How to Prioritize CVEs by Risk, Not Severity
  • Your MCP server on AgentCore Runtime fails its health check at `/mcp/`. Here’s how to fix it.
  • Severity is no longer a triage input. Risk scoring you own is.
  • Generate least-privilege EventBridge policies and restrict access to your AWS Organization with k9-cdk
  • Building Evals for an AI Agent: From Zero to Consistency Testing

Recent Comments

    Copyright 2026 K9 Security Inc.