Securing AI Agents — MCP, Agentja...
Securing AI Agents — MCP, Agentjacking & the New Attack Surface (2026)

Tech Updates by Andres Sarmiento

Episode notes
In June 2026, researchers took over AI coding agents — Claude Code, Cursor, Codex — with no phishing, no malware, and a public credential developers paste into their own apps. It worked 85% of the time. The vendor's response? "Technically not defensible. We're not fixing it." Welcome to the new attack surface nobody secured. What you'll hear: • What MCP (Model Context Protocol) is — "USB-C for AI" — and why it became an unreviewed internet-facing doorway • The hygiene problem — Knostic verified exposed MCP servers; 100% had no authentication; 8,000+ reported by early 2026 • Agentjacking — how a public Sentry DSN let attackers poison the logs an agent reads (85% success, 2,300+ orgs) • The pattern — prompt injection (OWASP's #1 AI risk), indirect injection, and last year's Black Hat zero-click CRM exfiltration • The readiness gap — 83% of orgs deplo ... 
Read more