Loading posts ...

A Security Leader’s Guide to Latio’s 2026 AI Security Market Report

A practical breakdown of Latio’s 2026 AI Security Market Report, what security leaders should look for, and why Pluto was recognized as an Endpoint AI Security Leader.
Read More

MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments

A working exploit for MCPfluence appeared on a cybercrime forum just 20 days after responsible disclosure. Pluto Research traces the attack path, examines similar exploitation…

Malicious Servers, Clean Scans: The Dangerous Illusion of a Clean MCP Scan

Pluto Research tested five public MCP security scanners against malicious servers. Several returned clean or zero-finding results, exposing the gap between what a scan checks…
Read More

Introducing MCP Inspector: Know an MCP Server’s Risks Before You Install It

Meet MCP Inspector, a free tool from Pluto Research that checks MCP servers for security risks before you install them. Built from the findings behind…

Enterprise AI Guardrails: How to Build Policy Enforcement That Actually Works

The rapid adoption of Generative AI, which has evolved from experimentation to enterprise-wide use, has revealed a critical reality: most organizations have AI policies, but…

Your CI Pipeline Is a Credential Vending Machine: 7 Lessons from the TeamPCP supply-chain attacks

TeamPCP turned trusted automation into a path for credential theft and lateral compromise. Based on 37 mapped incidents, here are seven controls defenders should prioritize…

The Manipulated Agent: When Apify’s MCP Turns Against You

Apify's official MCP connector let a scraped web page trigger a second, authenticated Apify action nobody asked for. Chapter 3 of Operation: MCP breaks down…
Read More