Latest posts
AI Security
MCP10 - Context Injection & Over-Sharing
The answer is correct. The sources are not.
AI Security
MCP09 - Shadow MCP Servers
The tool works. That is what makes it hard to notice.
AI Security
MCP08 - Lack of Audit and Telemetry
MCP07 was about whether an action was allowed. This one is about whether anybody can tell it happened.
AI Security
MCP07 - Insufficient Authentication & Authorization
MCP06 was about an agent doing the wrong job. This one is about whether it was allowed at all.
AI Security
MCP06 - Intent Flow Subversion
In MCP05 a string became command syntax and the agent decided nothing. Here the agent decides, and it decides wrong.
AI Security
MCP05 - Command Injection & Execution
In MCP04 somebody else's code shipped. Here your own code runs somebody else's command.
AI Security
MCP04 - Software Supply Chain Attacks & Dependency Tampering
MCP01 took the tokens. MCP02 took the permissions. MCP03 poisoned the tools. Now let's take the code nobody wrote.
AI Security
MCP03 - Tool Poisoning
In MCP01 we took the tokens. In MCP02 we took the permissions. Now we go after the agent itself.
AI Security
MCP02 - Privilege Escalation via Scope Creep
In MCP01 we took the tokens. Now let's take the permissions.
AI Security
MCP01 - Token Mismanagement & Secret Exposure
In Part 1 we got the basics right. Now let's steal some tokens.
AI Security
MCP Hacking - Basics
Before we start hacking MCP servers, let's get basics right.