About the author

Ehud is a security researcher at Pluto Security, specializing in vulnerability research across AI tools, MCP servers, and emerging agent-based systems.

He brings deep cybersecurity expertise honed during his service in Unit 8200, where he led multidisciplinary projects spanning research and engineering. After his service, Ehud joined Pluto to help defenders move faster than attackers in the AI era – driven by a first-principles approach to understanding how systems really work.

Related Posts

Wide Open: Hundreds of MCPs Exposing Root Shells, Production Data, and Citizen Records One Call Away

Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing everything from root access and production credentials to financial…
Read More

Inside Claude Code Function Hooks: The Trust Problem Behind Claude Mods

Pluto Research tested Claude Code’s new function-hook model and found four trust gaps, including silent secret access, missing capability disclosure, UI spoofing, and code that…

Introducing MCP Inspector: Know an MCP Server’s Risks Before You Install It

Meet MCP Inspector, a free tool from Pluto Research that checks MCP servers for security risks before you install them. Built from the findings behind…

Inside Claude Artifacts – How Your Agent Publishes to the Web

TL;DR Claude Artifacts are live web pages built from model output. Ask for a dashboard and you get a real URL on Anthropic infrastructure, rendered…

The Importer Syndrome × Count Dooku 2.0 – When Your New AI IDE Imports More Than Extensions

How a gap between Microsoft Marketplace and Open VSX lets attackers hand you malware under trusted names, and the 150-extension campaign already exploiting it. TL;DR…

Inside Claude Office Add-ins – What Gets Sent, What Gets Bypassed, What Goes Unrecorded

TL;DR Claude’s Office Add-ins place a Claude task pane alongside your Word, Excel, and PowerPoint documents and let the model read, edit, and act on…