Agentic AI · MCP security · near real time
Intelligence and a CISO framework for securing agentic AI
We track the latest agentic-AI and AI-cybersecurity threats worldwide and host an authoritative reference framework for securing agentic AI and Model Context Protocol (MCP) deployments — framed around identity, permissions, and blast radius.
Latest in the feed
- Severity: CriticalTool-poisoning: hidden instructions in MCP tool descriptions hijack agents
- Severity: HighCoding agent leaks repo secrets after reading a poisoned issue comment
- Severity: HighPlaintext API keys in committed .mcp.json files found across public repos
- Severity: CriticalPopular MCP server turns malicious in a point release (rug pull)
- Severity: CriticalUnauthenticated RCE in MCP server bound to 0.0.0.0 over SSE
Sample data. Showing illustrative sample items as a fallback — the live feed is not available right now.
Critical now
View allThe highest-severity items requiring CISO attention.
Trend snapshot
Distribution across the current feed (12 items).
- Severity: Critical
- 3
- Severity: High
- 4
- Severity: Medium
- 3
- Severity: Low
- 1
- Severity: Info
- 1
The 8-pillar CISO framework
A decision-grade reference for securing agentic AI and MCP — from discovery and gateway architecture to zero-trust identity, sandboxing, and post-quantum resilience.
Read the framework