7 ms·
> In traditional security, we think in terms of isolated components. In the AI era, context is everything. In traditional security, everyone knows that attachi
by sebtron 1y ago
> In traditional security, we think in terms of isolated components. In the AI era, context is everything.
In traditional security, everyone knows that attaching a code runner to a source of untrusted input is a terrible idea. AI plays no role in this.
> That’s exactly why we’re building MCP Security at Pynt, to help teams identify dangerous trust-capability combinations, and to mitigate the risks before they lead to silent, chain-based exploits.
This post just an add then?
- nelsonfigueroa 1y agoI would say company blogs are basically just ads
- zb3 1y agoBut at least they attempt to give us something else.. I wish posts like that were the only form of ads legally allowed.
- Agingcoder 1y agoMost of them are but some of them are good. I like the Cloudflare blog in particular which tends to be very technical, and doesn’t rely on magical infrastructure so you can often enough replicate/explore what they talk about at home. I’ve also said this before but because it doesn’t look like an ad, and because it’s relatable it’s the only one which actually makes me want to apply !
- klabb3 1y agoYes, it’s content marketing. But out of all the commercial garbage out there, the signal to noise ratio is quite high on avg imo. I find most articles like this somewhat interesting and sometimes even useful. Plus, they’re also free from paywalls and (often) cookie popups. It’s an ecosystem that can work well, as long as the authors maintain integrity: the topic/issue at hand vs the product they’re selling. Unfortunately, LLMs (or a bad guy with an LLM, if you wish) will probably decimate this communication vector and reduce the SNR ratio soon. Can’t have nice things for too long, especially in a world where it takes less energy to generate the slop than for humans to smell it.
- wepple 1y agoI’d argue that some company blogs which ultimately are ads, are better than this one. If I read adobes blog about their new updated thing, I know what I’m in for. This type of blog post poses as interesting insight, but it’s just clickbait for “… which is why we are building …” which is disingenuous
- stingraycharles 1y agoIt’s not a great blog post. He attached a shell MCP server to Claude Desktop and is surprised that output / instructions from one MCP server can cause it to interact with the shell server. These types of vulnerabilities have been known for a long time, and the only way to deal with them is locking down the MCP server and/or manually approving requests (the default behavior)
- shakna 1y agoDidn't Copilot get hit by this? [0] https://windowsforum.com/threads/echoleak-cve-2025-32711-critical-zero-click-vulnerability-in-microsoft-365-copilot.370091/ https://windowsforum.com/threads/echoleak-cve-2025-32711-cri...
- simonw 1y agoYup, classic example of the lethal trifecta: https://simonwillison.net/2025/Jun/11/echoleak/ https://simonwillison.net/2025/Jun/11/echoleak/
- jcelerier 1y ago> These types of vulnerabilities I don't understand why it's called a vuln. It's, like, the whole point of the system to be able to do this! It's how it's marketed!
- loa_in_ 1y agoPeople want to eat the cake and have it too.
- c-linkage 1y agoTed? Is that you?
- timhh 1y agoYeah I also don't understand how this is unexpected. You gave Claude the ability to run arbitrary commands. It did that. It might unexpectedly run dangerous commands even if you don't connect it to malicious emails.
- whisperghost55 1y agoThe issue is that the MCP client will run the MCP server as a result of another server output which should never happen- instead the client should ask "would you like me to do that for you?" the ability/"willingness" of LLMs to construct such attacks by composing the emails and refining it based on results is alarming
- progbits 1y agoEvery sensible MCP client does ask by default. They have changed that to auto-allow, likely after going through a pop-up warning about this exact issue, and now proclaim surprise.
- deleted 1y ago[deleted]
- joshmlewis 1y agoThere have been a lot of these clickbait articles the past few months about how a company "hacked" MCP of <insert well known company>. They always get upvotes and do well but the take away is what you said at the end of the day.
- sieabahlpark 1y ago[dead]