Security
Cycode found a vulnerability that let an MCP server steal OAuth credentials
Upgrade the SDK to version 2.2.0 or 1.30.0 to remove the vulnerability.
What matters in AI.
SubscribeNews category
32 stories, newest first.
Security
Upgrade the SDK to version 2.2.0 or 1.30.0 to remove the vulnerability.
Security
The text works in only about 35% of tests at most, and it is always plaintext, which tools can find.
Security
The attacks made the data of 68,000 or more customers open to the attackers.
The SOFX ReportClaimed, not confirmed
Security
The authors tell that the monitor also gave an alarm for 29.3% of safe runs.
arxiv.orgClaimed, not confirmed
Security
The authors put malicious prompts in data that looks safe, and the attack works only after a world model uses the data.
arxiv.orgClaimed, not confirmed
Security
The authors found a false-positive rate of 0.1%, and the system limits the model to a closed set of commands.
arxiv.orgClaimed, not confirmed
Security
The researchers find a success rate of more than 95% for the attack.
arxiv.orgClaimed, not confirmed
Security
The attack can also get around 3 agent-level defenses.
arxiv.orgClaimed, not confirmed