Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP is the New Attack Surface -- and Your Controls Probably Don't Cover It #ai #mcp

AI just handed attackers a new front door — and most security teams don't even know it exists. Model Context Protocol (MCP) is the emerging standard that lets AI agents talk to your tools, your data, and each other. It's also the most significant new attack surface to emerge in years. The NSA noticed. Your adversaries already have.

5 Mindset Shifts for Security Teams with Gal Yosef

In this episode, Gal Yosef, Head of Product Management at AlgoSec, explores the five critical mindset shifts security teams must make to successfully secure today’s hybrid and multi-cloud environments. As organizations expand across AWS, Azure, GCP, and on-premises infrastructure, traditional security approaches often create silos, visibility gaps, and operational complexity.

Bridging the gap: How Corelight and Crowdstrike Charlotte AI are redefining SOC investigations

For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior. This manual back-and-forth isn't just tiring; it’s a window of opportunity for attackers. Corelight is excited to highlight a new integration with CrowdStrike Charlotte AI.

How to overcome data gravity and accelerate AI security in the SOC

Security teams ingest massive volumes of telemetry from endpoints, cloud workloads, identity providers, and network controls. The goal is faster threat detection and shorter incident response times. But the reality is that all of this data becomes harder to move, slower to query, and messier to analyze as it grows. That's data gravity, and it's the biggest barrier to effective AI in cybersecurity.

Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers

Scammers are using legitimate hotel booking details to craft targeted phishing attacks, WIRED reports. Victims are far more likely to fall for a phishing attack if a message contains real information that they wouldn’t expect a scammer to know. According to researchers at Norton, this phishing campaign is targeting customers of at least 350 hotels and vacation rentals across 50 countries.

Warning: Scammers are Exploiting Geopolitical Unrest

Scammers are taking advantage of the conflicts in the Middle East and Ukraine to exploit people’s emotions, according to researchers at ESET. “Geopolitical turmoil often leads to human misery, which tends to pull at the heartstrings,” ESET says. “Legitimate charities may solicit donations to help their efforts to support innocent citizens caught in the crossfire.

Athletes Are Increasingly Targeted by Social Engineering Attacks

Scammers are increasingly targeting athletes with advanced social engineering attacks, the Guardian reports. The Guardian cites a recent report from Ernst & Young that found that athletes and teams have lost nearly $1 billion to fraud over the past twenty years, and more than 40% of these losses were reported in the past six years.

From Small Town to Global Clients - Growth, AI & Cash Flow Lessons | Podcast with V Gautham Navada

V Gautham Navada, founder of ForthFocus, shares his entrepreneurial journey from freelancing in a small town to serving 350+ clients across 8+ countries. The discussion centered around "forthfocus" and its "10 Years of Vision, Innovation & Growth.