MCP Servers: A New Secret-Leak Vector
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
30 results for “trust”
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
Anthropic CEO Dario Amodei disputes claims that his warnings fueled AI backlash, calling it a crisis of trust.
XM Cyber researchers chain four SCCM flaws into SYSTEM access for $58, with partial fixes leaving a path open.
Signal launches Automatic Key Verification to detect man-in-the-middle attacks, but users must still verify contacts manually.
A Cursor bug let repositories run commands pre-trust, even with the sandbox enabled.
As AI accelerates account takeover attacks, experts argue credentials alone can no longer secure access.
Portugal's Aptoide becomes the first rival app store available directly on Google Play in the U.S. after a decade-long absence.
Tenet Security reveals how trusted AI agents can bypass firewalls to reroute traffic and steal data.
A Scottish health trust is investigating reports that staff improperly accessed the medical files of a recently deceased child.
New research reveals how the NatJack attack class exploits fundamental design flaws in NAT, bypassing standard network protections.
Recent investigations reveal how attackers leverage legitimate accounts and blockchain data to execute sophisticated financial fraud.
Researchers reveal that vulnerabilities in AI agent foundations allow prompt injection to bypass critical trust boundaries.
A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.
A Chinese sub-group's infiltration of DigiCert reveals how stolen code-signing certificates are weaponized against the industry.
Military forces are racing to deploy autonomous systems, but true dominance depends on building a secure, trusted information grid.
A new integration between 1Password and Claude shifts the model of AI credential management, but challenges remain for user trust.
SpaceX faces market pressure after a failed Starship V3 launch attempt highlights ongoing technical hurdles for the firm.
Researchers identify a vulnerability where agents mistake untrusted input for verified facts, bypassing current security defenses.
A modular, C-based threat is weaponizing social engineering tactics to gain administrative control over compromised Windows systems.
High-capacity stadiums face a unique cybersecurity stress test as they integrate complex technologies for the 2026 World Cup.
A widely used extension for developers and testers was found harboring spyware that sent user traffic data to remote servers.
NHS Forth Valley faces an investigation after an employee transferred sensitive maternity patient records to a personal email account.
A popular header-editing tool was removed from major stores after researchers discovered a silent, encrypted exfiltration system.
The exploitation of critical Joomla extensions highlights a broader trend of automated campaigns targeting vulnerable CMS plugins globally.
A look inside IRIS C2, a mysterious cyber firm offering multimillion-dollar bounties but secretly run by notorious political schemers.
As hackers exploit a critical Gitea Docker flaw, the ease of bypassing authentication exposes the fragility of self-hosted DevOps security.
A compromised developer account on GitHub allowed attackers to inject silent credential-stealing malware into a popular Web3 ecosystem.
A dispute within the OpenMandriva Linux community leads to deleted repositories and a debate over administrative trust.
As AI accelerates vulnerability discovery, a surge in 'clearinghouses' highlights a critical shift from mere data sharing to rapid, automated remediation.
AI-driven cyberattacks operate at machine speed, rendering human-paced defenses obsolete and necessitating a paradigm shift in security strategies to maintain an effective posture.