Loading posts ...

Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record

Two vulnerabilities in CircleCI’s official MCP server: a CVSS 10.0 that turns a filename into code execution inside your CI pipeline, and a CVSS 8.3 that lets any website you visit drive your CI on…
Read More

Securing Claude Tag: A Practical Hardening Guide

Claude Tag’s security comes almost entirely from configuration – who can invoke it, what each channel and connected repo can reach, where its data can…

The Importer Syndrome × Count Dooku 2.0 – When Your New AI IDE Imports More Than Extensions

How a gap between Microsoft Marketplace and Open VSX lets attackers hand you malware under trusted names, and the 150-extension campaign already exploiting it. TL;DR…

Two New Gartner® Reports Point to Stronger Endpoint Controls in the AI Era, with Pluto Named as a Sample Vendor.

Most enterprises still make a binary call on AI: block it, or let it run and hope nobody notices. Two Gartner research notes published a…
Read More

MCP Security in AI Integration Protocols, Package Ecosystems, and External Tool Connections

The rapid adoption of Model Context Protocols (MCPs) and AI integration technologies that standardize communication between models and external systems has led to new security…

Inside Claude Tag: How Anthropic’s Slack-Native Agent Actually Works

Claude Tag drops an autonomous, credentialed AI agent into your Slack – one that acts under its own identity, can be summoned by anyone in…

Total Recall: How Two CVEs Let Any Website Read, Rewrite, and Wipe Your AI’s Memory

CVE-2026-33010 (CVSS 8.1) and CVE-2026-29787 (CVSS 5.3) in mcp-memory-service – a popular “second brain” for AI assistants – let a single malicious link silently steal,…