Skip to main content
Sonya Moisset

Sonya Moisset

France

👋 Bonjour! I’m an AI Security Leader & Evangelist 🥑 and a lifelong traveler. Always looking for new challenges - I made a career change from International Business Consulting in 🇹🇳, 🇸🇦 and 🇸🇬 to Engineering in 🇰🇷 to Cybersecurity in the 🇬🇧. 💖 Passionate about DevSecOps, Cybersecurity and AI ☁️ OpenUK Security Advisory Board Member & 2x OpenUK Honoree 🎓 3x CyberGirls fellowship mentor 🪲TryHackMe room creator ✍️ 6x Top contributor for freeCodeCamp 🎤 International public speaker, Tech advocate & Mentor 😀🌍🇫🇷🌈🦄🍱✈️💻☕️🎧🎬📷🕹️

Links. Selecting an option opens the link in a new tab.

Community Contributions

Is MCP becoming the new API security problem?

Model Context Protocol (MCP) started with a relatively simple idea: give AI applications a standard way to discover and use tools. An agent could connect to a database, SaaS platform, API, filesystem or internal service without every integration requiring a completely different interface. That simplicity is part of what made MCP attractive. But as MCP moves into enterprise environments, the security problem is becoming considerably more complicated.

Article/Publication / 08-28-2026

Can Prompt Injection ever actually be solved?

Prompt injection has become one of the defining security problems of generative AI. We have spent the last few years looking for better system prompts, stronger instruction hierarchies, improved model alignment, input filters, classifiers and sophisticated guardrails. Yet the fundamental problem has not disappeared: an AI system is being asked to interpret instructions and content that may come from sources it does not fully trust. Once that system can also retrieve sensitive data, invoke tools or take actions, the consequences of getting that interpretation wrong become considerably more serious.

Article/Publication / 08-27-2026

What does Least Privilege mean for an AI agent?

Least privilege is one of the oldest principles in security: give a principal only the authority required to perform its function, and no more. For decades, the model was relatively straightforward. A human user, application, process, or service account had an identifiable role, a defined set of resources, and a set of permissions that could be reviewed and reduced over time. Authorization could be designed around a relatively stable relationship between a principal, an action, and a resource.

Article/Publication / 08-26-2026

Related Stars