About the author

Yotam Perkal leads Security Research at Pluto Security, where he focuses on securing AI-native development environments and uncovering emerging risks in AI-driven software workflows. With over a decade of experience in cybersecurity, his work sits at the intersection of offensive research, vulnerability management, and software supply chain security.

Previously, Yotam led Threat Research at Zscaler, headed Vulnerability Research at Rezilion, and held multiple roles within the PayPal security organization.

He is an active contributor to cross-industry initiatives focused on AI security, vulnerability management, and software supply chain risk.

Related Posts

Skills, Connectors, Plugins, Oh My: A Security Practitioner’s Map of the Claude Extension Ecosystem

TL;DR Three primitives, one trust radius. Skills, Connectors (MCP), and Plugins look like distinct architectural units but are effectively a bundle. A single plugin installation…

Agent Skills Supply Chain Risks

Supply Chain Risks of Agent Skills AI agents are rapidly evolving from simple automation tools into complex systems capable of performing a wide range of…

Inside Claude Managed Agents: Reverse-Engineering the Security Boundaries of Anthropic’s Hosted Agent Runtime

In our previous deep dive into Claude Cowork, we reverse-engineered Anthropic’s desktop agent – uncovering gVisor syscall filtering, MITM TLS inspection proxies, and a layered…

Software Supply Chain Attack: How the AI Agent Ecosystem Became a New Battleground

The software ecosystem has undergone a fundamental shift with the emergence of AI agents. Applications are no longer built from isolated codebases. They are now…

Securing Claude Managed Agents: What You Need to Know Before Going to Production

Claude Managed Agents is Anthropic’s hosted agent runtime – a platform where Claude runs autonomously in cloud containers with bash access, file I/O, web browsing,…

Securing Claude Cowork: What Security Teams Actually Need to Know

Claude Cowork is Anthropic’s autonomous desktop agent. Unlike a chatbot that responds to prompts, Cowork takes a goal, then independently reads files, writes code, browses…

MCPwn: A CVSS 9.8 One-Line MCP Bug That Hands Over Your Nginx to Anyone on the Network – Actively Exploited in the Wild

What if a single missing function call – one middleware reference, 27 characters – could give any attacker on your network complete control over your…

Inside Claude Cowork: How Anthropic’s Autonomous Agent Actually Works

We reverse-engineered the security architecture of Claude’s autonomous desktop agent. Here’s what we found. Computer use agents represent a new class of AI capability: systems…

Another Day, Another Supply Chain Compromise: Here’s What We Know About the Axios Incident

A maintainer account takeover, a cross-platform RAT, and a payload designed to vanish – inside the axios npm compromise and why network-level detection matters more…