Hacker News new | ask | show | jobs
Official Azure MCP exploited to steal users Keyvaults secrets (tramlines.io)
4 points by coderinsan 340 days ago
1 comments

Tramlines.io presents: Another day, another official MCP server exploited. Again.

Why on earth does Azure need an MCP server? MCPs do not belong anywhere near a critical system responsible for storing sensitive secrets or env vars.

Now the official Azure MCP server can be breach with all your key-vault secrets exfiltrated.

I think this tells you that "MCP" is rising to becoming the worst protocol standard that has ever been designed.

And once again, no-one cares. (they really should)