Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP Supply Chain Security: How Malicious MCP Servers Are Infiltrating Enterprise AI Environments

Every enterprise deploying AI agents is building on a foundation of third-party MCP servers they don’t control, can’t verify, and barely track. The security conversation keeps focusing on the model – prompt injection, jailbreaks, hallucinations. That’s the wrong place to look. We’ve covered why that framing falls short elsewhere too – see System Prompts Are Not Security Boundaries. Business Logic Graphs Are.

Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry

A malicious release of @injectivelabs/sdk-ts, an npm package that pulls around 50,000 weekly downloads, shipped code that records wallet mnemonics and private keys as they are derived and ships them to an attacker-controlled endpoint. The bad version, 1.20.21, was live on npm for under an hour on June 8, 2026 before the maintainer noticed and published a clean fix.

AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors

Pentesting made sense when releases happened every few months. A point-in-time assessment could provide an accurate picture of risk for weeks, sometimes months. Today, engineering teams ship continuously. Our State of AI in Pentesting survey of 200 CISOs and 200 engineering leaders, found that 76% deploy significant changes at least weekly, while nearly 40% deploy daily. Yet only 21% validate security on every release. That gap has consequences.

Prompt Injection and the Rise of Agentic Risk

Boxers will often say, the punches that hurt the most aren’t the ones which are thrown with the most force, but the ones they didn’t see coming. I think the same is true in cybersecurity. It’s not the most advanced technically efficient, 0-day utilizing attacks that have the biggest impact, but rather those quiet ones. With no malware or suspicious login at three in the morning from an IP address in a country your company has never done business with. No alert fires.

WireGuard vs OpenVPN: What Actually Matters for Everyday VPN Security?

Many people look at the protocol first when choosing a VPN. WireGuard sounds newer and faster. OpenVPN sounds mature and dependable. The question quickly becomes: which one is safer? It is a useful question, but it is not complete. VPN protocols do matter. They help decide how the encrypted tunnel is created, how the connection is verified, and how data moves between your device and the VPN server. But in real use, a VPN is not trustworthy just because it supports a certain protocol.

When the Classifier Is the Judge: What the Adelphi AI Case Reveals About Automated Verification

Orion Newby was a student at Adelphi University when a single automated score nearly ended his academic career. He had written a course paper himself, working with tutors from a university support program for students with learning and neurological differences. The essay was run through an AI detector, which reported it as AI-written. On the strength of that output, Newby was accused of an integrity violation, the kind of charge that can escalate toward suspension or expulsion on a repeat offense.

Why Doctors Recommend an Upper Endoscopy

Understanding the reasons for endoscopy can help ease the anxiety that often comes with medical procedures. For many patients, especially seniors, hearing that a doctor has recommended a diagnostic test can be concerning. However, an upper endoscopy is a routine and highly effective tool used to examine the digestive tract. It allows medical professionals to visually inspect the esophagus, stomach, and the first part of the small intestine (duodenum) to diagnose and treat various conditions.

5 Best SD-WAN Products With Centralized Network Policy Management

Managing network policy across a distributed enterprise has always been complex. Each branch office, remote location, and cloud connection point represents a potential gap between policy and enforcement. In traditional WAN environments, that gap often meant shipping preconfigured devices to each location, maintaining separate management platforms for different network functions, and accepting that configuration drift across dozens or hundreds of sites was largely inevitable.