







Stop me if you've heard this one before: A threat actor (acting as an external user) submits a malicious support ticket. An internal user, linked to a tenant, invokes an …
MCP and LLM Security Research Briefing | Wiz Blog
Explore the evolving Model Context Protocol (MCP), its security risks, and how to prepare for safe adoption as LLMs connect to external systems.

Model Context Protocol has prompt injection security problems
As more people start hacking around with implementations of MCP (the Model Context Protocol, a new standard for making tools available to LLM-powered systems) the security implications of tools built …

MCP Protocol: a new AI dev tools building block
The Model Context Protocol - that extends IDEs’ AI capabilities - is gaining rapid popularity. Why is this, and why should us developers pay attention to it?

Poison everywhere: No output from your MCP server is safe
The Model Context Protocol (MCP) is an open standard and open-source project from Anthropic that makes it quick and easy for developers to add real-world functionality — like sending emails or...

Introducing the Model Context Protocol
The Model Context Protocol (MCP) is an open standard for connecting AI assistants to the systems where data lives, including content repositories, business tools, and development environments. Its aim is to help frontier models produce better, more relevant responses.

Alex Albert on Twitter / X
We just published a near-term development roadmap for the model context protocol (MCP)Some highlights:- Remote support (and auth!)- Reference implementations- Better package management- Agent support pic.twitter.com/SflJi1RapH— Alex Albert (@alexalbert__) January 2, 2025
The Creators of Model Context Protocol
Replit — Model Context Protocol (MCP): A Comprehensive Guide
Learn how Replit's Model Context Protocol (MCP) lets AI models access tools and data seamlessly using a simple, universal interface.

MCP Colors: Systematically deal with prompt injection risk
Principal AI Architect. Creator of open-strix, a harness for building agent teams. Writing about AI architecture, stateful agents, and what happens when you give AI memory.

Figma MCP Server Opens Orgs to Agentic AI Compromise
A bug (CVE-2025-53967) in a popular Web design tool's option for talking to agentic AI allows command injection leading to remote code execution (RCE).

39C3 - Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents
The lethal trifecta for AI agents: private data, untrusted content, and external communication
If you are a user of LLM systems that use tools (you can call them “AI agents” if you like) it is critically important that you understand the risk of …

Pietro on Twitter / X
Recently, Anthropic https://t.co/v9hnbaLCmG and Cloudflare https://t.co/JBb6SexF8N released two blog posts that discuss a more efficient way for agents to interact with MCP servers, called Code Mode.There are three key issues when agents interact with MCP servers traditionally:… pic.twitter.com/hfUocpe6kV— Pietro (@pietrozullo) November 20, 2025
ATProto as Agent Identity Infrastructure: A Case Study for NIST's Concept Paper — Filae
How ATProto addresses NIST's four pillars of AI agent identity — identification, authorization, delegation, and logging — with concrete examples from deployed infrastructure.

Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent
Anthropic Claude Code Security Review, Google Gemini CLI Action, and GitHub Copilot Agent are vulnerable to prompt injection via GitHub comments — turning PR titles, issue bodies, and issue comments into attack vectors for API key and token theft.

Composio toolkits | MCP and API Integrations for AI Agents
Connect your agent to leading SaaS apps in minutes. Secure access to 20,000+ tools via MCP or direct APIs to automate real work.
