|
|
|
|
|
by IMAYousaf
302 days ago
|
|
This is definitely valuable. I started paying attention to MCP security vulnerabilities largely because of Defcon. I believe that they largely focused on Agentic Security as a theme this time around. It's a bit mind blowing how we've simply accepted non-technical people within orgs in particular executing code to "automate their tasks" without the same level of rigor that normal code reviews go through. Definitely think that this is a cultural issue that we must fix. And these MCP vulnerabilities in particular seem much scarier because almost all MCP tools require an insane amount of permissions. |
|