Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

Model Context Protocol (MCP) is what turns an AI assistant into an AI agent. It’s the standardized bridge that lets models call real tools – read files, query databases, send messages, pull emails. That capability is the whole point. It’s also what makes MCP environments a target. Most deployments were scoped for what the agent needed to do. Not for what happens when that access is turned against the organization.

The Top 5 Questions Security Leaders Are Asking About Coding Agents

The discussion during our recent webinar made one thing clear. Security teams aren't asking whether coding agents will become part of the enterprise. They're asking how to adopt them safely. The audience questions focused on practical concerns that many organizations are facing today, from autonomous execution to supply chain risk and governance. Here are the five questions that generated the most discussion.

Agentic AI Governance Requires a New Enforcement Model

AI has swiftly shifted from a browser-based chat interface to an autonomous actor operating within enterprise environments. Agents run locally on endpoints, inherit employee permissions, access sensitive data in bulk, and execute multi-step workflows with no human approving each step. That shift fundamentally changes the enforcement surface. The governance programs most organizations have built were designed for a different model: one user, one prompt, one decision.

Data leakage risks with DBHub MCP servers

Organizations keep their databases behind firewalls for a reason: the data inside is the data they can least afford to lose. A new class of AI middleware–Model Context Protocol (MCP) servers–exists specifically to reach into those protected systems on an AI model's behalf. One of them, DBHub, connects directly to SQL databases.

Coding Agents Are Moving Faster Than Security. Here's What CISOs Need to Know.

Coding agents have become one of the fastest-adopted AI technologies in the enterprise. They help developers write code, debug applications, automate repetitive tasks, and ship software faster than ever before. They also introduce a security challenge unlike anything most organizations have faced. Unlike traditional AI assistants that generate content, coding agents take action.

AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology

Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been republished here with the author's permission. It seems like every security vendor now sells "AI security." The WAF companies, the API gateway companies, the cloud platforms, the proxy startups: all of them have an AI story, and most of them have attached one of three labels to it. AI gateway. AI firewall. AI control platform. The terms often get used as if they're interchangeable, but they are not.

What Is Firewall Configuration and Why Is It So Important?

Firewall configuration is the set of rules, policies, and settings that define how a firewall behaves. Without configuration, a firewall is hardware and software waiting for instructions. With configuration, it becomes a control that determines what traffic is permitted, what is blocked, and what gets inspected before a decision is made. Get the configuration right, and the firewall does its job. Let it drift, and you have the appearance of protection without the substance of it. This is not an edge case.

AI Governance on AWS: Discover, Observe, and Control AI in Production

AI adoption within AWS environments is accelerating faster than most security and governance programs. AI agents, APIs, MCP servers, and model integrations are entering production across cloud environments, often without centralized visibility or runtime controls. In this webinar, you’ll see how teams can discover AI workloads across AWS accounts, understand what AI systems are actually doing at runtime, enforce policy in real time, and generate continuous governance evidence without slowing engineering teams down. The session focuses on practical operational capabilities for AI systems already running in production.