Securing AI Agents — MCP, Agentjacking & the New Attack Surface (2026)
Tech Updates di Andres Sarmiento
Note sull'episodio
In June 2026, researchers took over AI coding agents — Claude Code, Cursor, Codex — with no phishing, no malware, and a public credential developers paste into their own apps. It worked 85% of the time. The vendor's response? "Technically not defensible. We're not fixing it." Welcome to the new attack surface nobody secured.
What you'll hear:
• What MCP (Model Context Protocol) is — "USB-C for AI" — and why it became an unreviewed internet-facing doorway
• The hygiene problem — Knostic verified exposed MCP servers; 100% had no authentication; 8,000+ reported by early 2026
• Agentjacking — how a public Sentry DSN let attackers poison the logs an agent reads (85% success, 2,300+ orgs)
• The pattern — prompt injection (OWASP's #1 AI risk), indirect injection, and last year's Black Hat zero-click CRM exfiltration
• The readiness gap — 83% of orgs deplo ...
Leggi dettagli