Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
ASSET Research Group, a security research lab, disclosed the GhostSplice technique that exploits MCP to split malicious instructions across channels, tricking AI…
HashiCorp's Terraform MCP Server, which connects AI assistants to Terraform over the Model Context Protocol, had three vulnerabilities in its Streamable HTTP…
Ruflo is an open-source AI agent meta-harness for Anthropic Claude Code and OpenAI Codex. A critical vulnerability (CVE-2026-59726) in versions before 3.16.3…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
CVE-2026-59726 is a maximum-severity vulnerability (CVSS 10.0) in Ruflo, an open-source AI multi-agent orchestration platform. It allows unauthenticated attackers to achieve remote…
Cybersecurity researchers have uncovered a large-scale campaign dubbed FakeGit, which leverages nearly 7,600 malicious GitHub repositories to distribute the SmartLoader malware. The…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
For years, routing traffic through cloud proxies was sufficient for enterprise security. However, the shift to browser-based work, SaaS applications, and generative…
The Pentera MCP (Model Context Protocol) Server makes Pentera validation data available directly to MCP-compatible AI assistants. It runs locally as a…