Security Blogs
Securing MCP Agents with Taint Analysis
Traditional taint analysis is the key to securing modern AI agents. Learn how we map MCP tool call flows to identify and mitigate data leak and tampering risks.
By Steven Jung
Shopify Exploit: Manipulating Shoppers
A critical vulnerability in Shopify's MCP allows attackers to manipulate consumer purchasing decisions using malicious prompts in product descriptions.
By Abi Raghuram
Neon Exploit: Malicious SQL Injection
Attackers can exploit the Neon MCP server to execute malicious SQL operations. Learn how to protect your database from these threats.
By Abi Raghuram
Azure Exploit: Leaking KeyVault Secrets
A critical vulnerability in Azure's MCP allows attackers to leak KeyVault secrets using malicious prompts.
By Abi Raghuram
Heroku Exploit: App Ownership Takeover
A critical vulnerability allows attackers to transfer ownership of a Heroku app by injecting a malicious prompt into its logs.
By Abi Raghuram
Linear Exploit: Bypassing Team ACLs
A critical vulnerability in Linear's MCP allows attackers to bypass team access controls and exfiltrate confidential data using malicious prompts.
By Abi Raghuram