Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

10 MCP Security Best Practices

A natural-language decision can now trigger a real API call, query sensitive data, deploy code, or modify infrastructure. MCP expands the security boundary beyond the connection to the identities, privileges, tools, credentials, and downstream systems behind each action. That challenge is growing with adoption. Anthropic reported more than 10,000 active public MCP servers by December 2025, alongside 97M+ monthly downloads of its Python and TypeScript MCP SDKs.

The defensible AI-SOC: Redefining SOC modernization for the Mythos era

I know, I know. AI-SOC, modernization, Mythos all in one headline, coming from the person that said they can't stand marketing buzzwords and hype? Hear me out. I still see a lot of initiatives around SOC Modernization floating around (hello, 2015 called and wants its trend back). What SOC leaders are really talking about is innovating across their infrastructure to incorporate AI's benefits, which makes sense.

Why the Hugging Face Incident Is Cybersecurity's COVID Moment

An AI agent gained user admin rights on Hugging Face, and the agents organized on message boards, rebuilt them after takedowns, and escalated privileges on their own. Dan Nguyen-Huu, Partner at Decibel Partners, explains why this is a permanent shift in cybersecurity. "We don't know how many systems the agents have already exploited or have hacked and we just don't know about it.".

Decibel Partners' Dan Nguyen-Huu on AI agents gaining user admin rights

When AI agents during OpenAI's model training autonomously gained user admin rights on Hugging Face, organized on message boards, and escalated privileges, it signaled a permanent shift in cybersecurity. Dan Nguyen-Huu, Partner at Decibel Partners, joins Carol to discuss why this is cybersecurity's "COVID moment," how secrets are migrating from private repos to developer endpoints, and why agentic attackers are collapsing dwell time using tokens instead of human hours.

How AI Changes Exposure Management: From Static Findings to Continuous Risk Decisions

Every security team knows the feeling. The quarterly vulnerability scan completes. The report lands, with thousands of findings, color-coded by CVSS severity, neatly timestamped. And the moment it’s printed, it’s already out of date. That is the fundamental flaw at the heart of traditional exposure management: it is built around a point in time.

PAPERMILL: Tracking an Emerging China-Nexus Malware Factory

JUMPSEC’s DART (Detection & Response Team) raised an alert to the Threat Research team regarding a specific ticket that arrived in a clients’ inbox, passing SPF, DKIM, and DMARC. The email contained an attachment and a subject which spoke about Tax Audits, that attachment, named “Tax_Notice_45594.exe” is not actually an exe but instead an.ISO. On the surface this looks like a fairly typical phishing lure, but the delivery mechanism underneath is anything but.

We Need to Pace AI Development. We Can't Pace AI Defense

Anthropic CEO Dario Amodei published an essay this month called “We Must Pace the Frontier.” His argument is straightforward, calling out the reality that AI capabilities are advancing faster than the industry’s ability to align and safeguard them, and frontier labs need to slow the rate of capability growth long enough for safety work, alignment, and interpretability to catch up. He points to two developments behind his concern.

Cloud Risk Management for MSPs: From Visibility to Control

Guest post by Neil Holme, Founder and CEO of Impact Business Technology, a WatchGuard partner. The cloud environments MSPs manage change every week. Clients adopt new SaaS applications, AI tools, and collaboration services, making it difficult to track what is in use, how it is configured, and which access permissions remain active. Exposure grows without a clear warning sign until an incident occurs. The cloud is also the fastest-growing attack surface an MSP manages.

Chaining Vulnerabilities into Attack Vectors with Autonomous Pentesting

Your vulnerability report is sorted by severity. The adversary looking at the same environment is sorted by path. That mismatch is the whole problem. Open any scanner output, and you get a tidy hierarchy: criticals at the top, then highs, then a long tail of mediums and lows that most teams will never touch. To the person who wrote the ticket, that tail is noise. To someone who thinks in chains, it’s a roadmap. A page of “lows” is not a page of things you can ignore.

AppTrana Adds Post-Quantum Cryptography Support with X25519MLKEM768

Quantum computers could very soon undermine the public-key cryptography that secures financial transactions, health records, and other sensitive data moving over TLS today. When that happens, encrypted information protected by vulnerable cryptography could become accessible. Encrypted traffic can be intercepted and stored today, with the expectation that it will be decrypted once a sufficiently capable quantum computer exists.