Urgent.News

What's breaking now, across thousands of outlets.

AI

I built CyberMira: An AI-Powered Cybersecurity Assistant Grounded in Sanity

This is a submission for the Sanity Challenge, Path One: Ship an Agent That Queries Real Content What I Built Cybersecurity questions often have answers scattered across standards, vulnerability references, attack patterns, and mitigation guidance. CyberMira is an AI-powered cybersecurity assistant for developers that answers questions using a structured cybersecurity Knowledge Base instead of…

This project creates an AI-powered cybersecurity assistant named CyberMira specifically for developers. Traditional chatbots provide general knowledge, whereas CyberMira retrieves targeted cybersecurity information from a curated knowledge base before generating relevant answers. The knowledge base contains 36 structured entries covering topics like the OWASP Top 10, vulnerabilities, attack patterns, detection techniques, mitigations, technologies, and security references.

When a developer asks a question like "How can I prevent broken object-level authorization in a REST API?", CyberMira first identifies the relevant knowledge areas, retrieves the appropriate structured evidence from the Sanity Knowledge Base, and then feeds that evidence to the language model Gemini to create a grounded security response.

The architecture separates the retrieval of structured cybersecurity knowledge from the generation of explanations. Sanity serves as the structured knowledge layer, with a Knowledge Base ID (kbDqGgqkpnBN) and specific entries like vulnerabilities, technologies, attack patterns, detection techniques, mitigations, and OWASP categories.

The process involves selecting relevant knowledge paths based on the user's question, retrieving the corresponding evidence through Sanity Context MCP, and finally generating the answer using Gemini. The system demonstrates how structured content management systems like Sanity can be leveraged for complex reasoning tasks in specialized domains.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

Anthropic's Sonnet 5.5 release is about cost-per-task, not peak performance

Anthropic released Claude Sonnet 5.5 this week, and the main takeaway isn't a new state-of-the-art benchmark. The real story is the focus on cost-per-task for the bulk of everyday engineering work.

  • Anthropic releases Claude Sonnet 5.5 focusing on cost-efficiency
  • New model 30% faster and cheaper than Sonnet 5 for common tasks
  • Outperforms Sonnet 5 by 30% in agentic coding, 70.6% on Terminal-Bench 4.0

Adding AI to a Security Toolkit: Start With Your Own Scripts

Open your shell history before you open a course catalog. The jq filters, the grep -v chains against Zeek logs, the PowerShell one-liners you paste into a ticket every week: that is your toolkit.

  • Start with existing scripts like jq filters and PowerShell one-liners before adding AI.
  • Enhance existing pipelines (threshold adjustment, obfuscated script decoding, LLM features) with AI.
  • Train team on data paths and manual attacks to effectively use LLM in security pipelines.

More from Wednesday 30 September →