Loading posts ...

SleepyDuck Wakes Again: A Cross-Platform Open VSX Campaign Targeting Solidity Developer Workstations

Pluto Research traced EtherDuck, the latest evolution of SleepyDuck, through fake Solidity extensions, inflated download counts, and malware hidden inside a video file. The campaign established persistent access across Windows, macOS, and Linux, then returned…
Read More

Wide Open: Hundreds of MCPs Exposing Root Shells, Production Data, and Citizen Records One Call Away

Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing everything from root access and production credentials to financial…
Read More

Inside Claude Code Function Hooks: The Trust Problem Behind Claude Mods

Pluto Research tested Claude Code’s new function-hook model and found four trust gaps, including silent secret access, missing capability disclosure, UI spoofing, and code that…

A Security Leader’s Guide to Latio’s 2026 AI Security Market Report

A practical breakdown of Latio’s 2026 AI Security Market Report, what security leaders should look for, and why Pluto was recognized as an Endpoint AI…
Read More

MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments

A working exploit for MCPfluence appeared on a cybercrime forum just 20 days after responsible disclosure. Pluto Research traces the attack path, examines similar exploitation…

Malicious Servers, Clean Scans: The Dangerous Illusion of a Clean MCP Scan

Pluto Research tested five public MCP security scanners against malicious servers. Several returned clean or zero-finding results, exposing the gap between what a scan checks…
Read More

Introducing MCP Inspector: Know an MCP Server’s Risks Before You Install It

Meet MCP Inspector, a free tool from Pluto Research that checks MCP servers for security risks before you install them. Built from the findings behind…