Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 61 - Blind With Scissors: The NSA's MCP Warning for Every Agentic AI Deployment

The NSA just published a rare advisory on the Model Context Protocol (MCP)—the plumbing under nearly every agentic AI deployment of the last 18 months—and the verdict is stark: optional authentication, no token lifecycle, silent behavior changes, and no logging to catch any of it. Host Tova Dvorin sits down with defensive cybersecurity expert Adrian Culley to unpack the eight risk categories, the WhatsApp and GitHub MCP exploits, and why MCP is now a testable validation surface.

MCP is the New Attack Surface -- and Your Controls Probably Don't Cover It #ai #mcp

AI just handed attackers a new front door — and most security teams don't even know it exists. Model Context Protocol (MCP) is the emerging standard that lets AI agents talk to your tools, your data, and each other. It's also the most significant new attack surface to emerge in years. The NSA noticed. Your adversaries already have.

5 Mindset Shifts for Security Teams with Gal Yosef

In this episode, Gal Yosef, Head of Product Management at AlgoSec, explores the five critical mindset shifts security teams must make to successfully secure today’s hybrid and multi-cloud environments. As organizations expand across AWS, Azure, GCP, and on-premises infrastructure, traditional security approaches often create silos, visibility gaps, and operational complexity.

Bridging the gap: How Corelight and Crowdstrike Charlotte AI are redefining SOC investigations

For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior. This manual back-and-forth isn't just tiring; it’s a window of opportunity for attackers. Corelight is excited to highlight a new integration with CrowdStrike Charlotte AI.

How to overcome data gravity and accelerate AI security in the SOC

Security teams ingest massive volumes of telemetry from endpoints, cloud workloads, identity providers, and network controls. The goal is faster threat detection and shorter incident response times. But the reality is that all of this data becomes harder to move, slower to query, and messier to analyze as it grows. That's data gravity, and it's the biggest barrier to effective AI in cybersecurity.

Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers

Scammers are using legitimate hotel booking details to craft targeted phishing attacks, WIRED reports. Victims are far more likely to fall for a phishing attack if a message contains real information that they wouldn’t expect a scammer to know. According to researchers at Norton, this phishing campaign is targeting customers of at least 350 hotels and vacation rentals across 50 countries.