About the author

Yotam Perkal leads Security Research at Pluto Security, where he focuses on securing AI-native development environments and uncovering emerging risks in AI-driven software workflows. With over a decade of experience in cybersecurity, his work sits at the intersection of offensive research, vulnerability management, and software supply chain security.

Previously, Yotam led Threat Research at Zscaler, headed Vulnerability Research at Rezilion, and held multiple roles within the PayPal security organization.

He is an active contributor to cross-industry initiatives focused on AI security, vulnerability management, and software supply chain risk.

Related Posts

Nebula Deck: A Malicious VS Code Extension Built to Survive a Windows Reinstall

A fake project planner on the VS Code Marketplace starts working the second your editor finishes loading. It downloads a Windows script, unpacks a payload…
Read More

PhantomBoard: A Fake Trello Extension for VS Code That Quietly Installs XWorm

Three VS Code extensions, three throwaway publisher accounts, three days, and one backend IP address that never changed once. Read the source of these three…

Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record

Two vulnerabilities in CircleCI’s official MCP server: a CVSS 10.0 that turns a filename into code execution inside your CI pipeline, and a CVSS 8.3…
Read More

Securing Claude Tag: A Practical Hardening Guide

Claude Tag’s security comes almost entirely from configuration – who can invoke it, what each channel and connected repo can reach, where its data can…

The Importer Syndrome × Count Dooku 2.0 – When Your New AI IDE Imports More Than Extensions

How a gap between Microsoft Marketplace and Open VSX lets attackers hand you malware under trusted names, and the 150-extension campaign already exploiting it. TL;DR…

Inside Claude Tag: How Anthropic’s Slack-Native Agent Actually Works

Claude Tag drops an autonomous, credentialed AI agent into your Slack – one that acts under its own identity, can be summoned by anyone in…

Total Recall: How Two CVEs Let Any Website Read, Rewrite, and Wipe Your AI’s Memory

CVE-2026-33010 (CVSS 8.1) and CVE-2026-29787 (CVSS 5.3) in mcp-memory-service – a popular “second brain” for AI assistants – let a single malicious link silently steal,…

Count Dooku: A Live Malicious Open VSX Campaign Hiding in Plain Sight

Last updated: June 30, 2026 The most dangerous supply chain attacks are not always the loud ones. Over the last few days, Pluto Security has…

Introducing Plutonium

Over the past months we launched ClaudeSec for the Anthropic ecosystem and copilotsec.ai for the Microsoft one. Each closed the same gap in its own…