Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

Model Context Protocol (MCP) is what turns an AI assistant into an AI agent. It’s the standardized bridge that lets models call real tools – read files, query databases, send messages, pull emails. That capability is the whole point. It’s also what makes MCP environments a target. Most deployments were scoped for what the agent needed to do. Not for what happens when that access is turned against the organization.

Independence is the moat

Why the independent layer keeps winning as the models get better, not despite them. This series has been building to one question, and it is the objection every honest reader has been holding since the first piece. If the frontier models keep getting better this fast, why does an independent security layer keep winning? Why not wait for the model that writes safe code and verifies its own work?

Your Phone Number Is More Valuable to Criminals Than You Think

When people think about cybersecurity, they usually think about protecting passwords, laptops, or email accounts. Phone numbers don't make the list very often. Maybe they should. A phone number by itself isn't especially dangerous. Someone can't hack your phone simply because they know your number. But it is often the starting point for a much larger attack.

The best risk management software for enterprises

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.

Ten Black Hat NOCs and counting: Corelight sees it all

Whenever I come back from a Black Hat NOC, people always ask the same question: “So, what did you see?!” They understand how unique it is to have access to the detailed logs generated by an NDR overseeing the network traffic of a conference with thousands of attendees. There is always something to see. There are always stories that come out of the packets; those stories evolve into patterns, and the patterns offer the gift of lessons.

VMware VCF 9, VAIO with Zerto, and 11:11 DRaaS: What Our Customers Should Know Now

If you have been hearing more about vSphere APIs for I/O Filtering (VAIO) in Zerto conversations, there is a simple explanation: VAIO is VMware’s I/O filtering framework that has been created for Independent Software Vendors (ISVs) to build solutions on. Directionally, Zerto has supported this framework for some time and, coupled with VMware changes, this will be the preferred and default replication method used by Zerto in the not too distant future.

Immutable backup: Why it matters for ransomware recovery

Backups are often the last line of defense when ransomware reaches business-critical systems. But modern ransomware attacks do not target production data alone. Attackers may also search for backup repositories, compromise backup administrator accounts, change retention policies or delete recovery points before encrypting the live environment. When clean backup copies are no longer available, recovery becomes slower, more expensive and less predictable.