Figma AI Agents Boost Security, Find New Vulnerabilities

33m ago·0:00 listen·Source: infoq.com

Summary

Software company Figma is using AI agents to boost its security operations. Their engineering team built these agents to help investigate alerts, search past incidents, check systems, and even prepare code fixes. What's interesting is that these agents learn from previous investigations, which cuts down on repetitive tasks. This helps engineers resolve complex security alerts about 70% faster. Human review and strict controls are still firmly in place. The system uses various tools like Panther SIEM to investigate alerts across AWS, Okta, GitHub, and more than 100 other sources. This has also reduced on-call pages by 20% by lowering the severity of some alerts. The alert triage agent, which uses a model like Claude Opus, handles most of the investigation. The system’s effectiveness greatly improved through the use of different types of memory: past alerts, behavioral guidance, and learned database structures. Safety controls are also built in, like setting agent-created code fixes to draft by default. In a separate report, Figma's agents found over 100 previously unknown vulnerabilities, including two critical flaws missed by traditional tools. This kind of innovation means stronger security for the platforms we use every day.

Read the full article on infoq.com

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening