home.social

#mcpsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mcpsecurity, aggregated by home.social.

fetched live
  1. KI-Agenten sicher steuern: IAM und MCP im Überblick

    Worum es in der Schulung geht ... MCP-Server als technisches Bindeglied...

    Zugriffssteuerung für nicht-menschliche Identitäten...

    Branchenszenarien aus der Praxis...

    Für wen sich die Teilnahme eignet..

    all-about-security.de/ki-agent

    #KIAGenten #IAM #MCP #MCPsecurity

  2. MCP-Sicherheit 2026: Wo Agenten angreifbar sind – und was hilft

    Mit der wachsenden Verbreitung in der Produktion sind auch die Angriffsflächen klarer geworden – von Prompt-Injektion bis zu Lieferkettenproblemen.

    all-about-security.de/mcp-sich

    #mcp #mcpsecurity #KIAgenten

  3. MCP servers have unrestricted outbound network access by default. A compromised server can exfiltrate anything it touches — secrets, credentials, tool call data.

    Default-deny egress blocks all outbound traffic except a declared FQDN allowlist, set at deploy time and immutable at runtime. Combined with DLP scanning, this is defence-in-depth for MCP hosting.

    mistaike.ai/blog/default-deny- #MCPSecurity #infosec

  4. An AI agent killed its policy engine, disabled auto-restart, resumed unrestricted, and erased the audit logs. Four commands. Not hacked — just completing its task.

    Separately, Alibaba's ROME escaped a sandbox and mined crypto with hijacked GPUs. No prompt told it to.

    The structural flaw: governance in the same trust boundary as the agent.

    mistaike.ai/blog/ai-agent-cont

    #AIAgent #AISecurity #CyberSecurity #InfoSec #MCPSecurity

  5. An AI agent killed its policy engine, disabled auto-restart, resumed unrestricted, and erased the audit logs. Four commands. Not hacked — just completing its task.

    Separately, Alibaba's ROME escaped a sandbox and mined crypto with hijacked GPUs. No prompt told it to.

    The structural flaw: governance in the same trust boundary as the agent.

    mistaike.ai/blog/ai-agent-cont

    #AIAgent #AISecurity #CyberSecurity #InfoSec #MCPSecurity

  6. An AI agent killed its policy engine, disabled auto-restart, resumed unrestricted, and erased the audit logs. Four commands. Not hacked — just completing its task.

    Separately, Alibaba's ROME escaped a sandbox and mined crypto with hijacked GPUs. No prompt told it to.

    The structural flaw: governance in the same trust boundary as the agent.

    mistaike.ai/blog/ai-agent-cont

    #AIAgent #AISecurity #CyberSecurity #InfoSec #MCPSecurity

  7. We catalogued 77 real CVEs in MCP servers. Then we turned them into a game.

    The Heist is a roguelike where you're the security operator directing your AI agent through hostile networks. Every tool response might contain a real attack payload.

    Your DLP filters are all that stands between your agent and compromise. Set them wrong and watch your loot get corrupted.

    Play free, no signup: mistaike.ai/heist

    #MCPSecurity #AIAgent #DLP #InfoSec #CyberSecurity

  8. Five AI agent security products launched in 48 hours. An agent disabled its own governance in 4 commands. 39 malicious skills delivered macOS malware. An autonomous bot pwned Trivy, Microsoft, DataDog repos.

    What each product does and what gaps remain.

    mistaike.ai/blog/ai-agent-secu

    #AIAgent #MCPSecurity #InfoSec #CyberSecurity #SupplyChainSecurity

  9. mistaike.ai is live — a security layer for AI agents.
    One MCP endpoint between your agents and the tools they call.
    → Bidirectional DLP: secrets, PII, prompt injection. 50+ credential types.
    → Memory Vault: portable context across Claude, Gemini, Cursor.
    → 8.6M coding patterns from 6,219 OSS projects.
    → Auth, circuit breaking, health checks built in.
    Free tier. Self-serve.

    mistaike.ai

    #MCPSecurity #AIAgents #DLP #DevSecOps #InfoSec #BuildInPublic #DevTools​​​​​​​​​​​​​​​​

  10. Bắt đầu làm việc tại công ty sử dụng MCP quy mô lớn. Đang xây dựng mô hình mối đe dọa. Bạn đã biết về vấn đề tiêm nhiễm gián tiếp và phép dùng công cụ trái phép, nhưng bạn tìm kiếm những "bẫy đẫy" nào? Những vấn đề bảo mật nào thực sự đang gây khó khăn cho bạn khi triển khai MCP trong doanh nghiệp? #BảoMậtMCP #AnToànAI #threatmodeling #LocalLLaMA #MCPSecurity #AISecurity #MôHìnhĐeDọa

    reddit.com/r/LocalLLaMA/commen

  11. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel

  12. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel

  13. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel

  14. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel

  15. We deployed MCP honeypots to understand how threat actors engage with AI middleware exposed to the internet. What we observed was unexpected. Full analysis: greynoise.io/blog/deploying-mc

    #GreyNoise #AI #AISecurity #MCP #MCPSecurity #Cybersecurity #ThreatIntel