Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

Model Context Protocol (MCP) is what turns an AI assistant into an AI agent. It’s the standardized bridge that lets models call real tools – read files, query databases, send messages, pull emails. That capability is the whole point. It’s also what makes MCP environments a target. Most deployments were scoped for what the agent needed to do. Not for what happens when that access is turned against the organization.

Independence is the moat

Why the independent layer keeps winning as the models get better, not despite them. This series has been building to one question, and it is the objection every honest reader has been holding since the first piece. If the frontier models keep getting better this fast, why does an independent security layer keep winning? Why not wait for the model that writes safe code and verifies its own work?

Your Phone Number Is More Valuable to Criminals Than You Think

When people think about cybersecurity, they usually think about protecting passwords, laptops, or email accounts. Phone numbers don't make the list very often. Maybe they should. A phone number by itself isn't especially dangerous. Someone can't hack your phone simply because they know your number. But it is often the starting point for a much larger attack.

What's new in Active Roles 8.5

Active Roles by One Identity version 8.3 provides several highly requested features to fortify and enrich the integration capabilities of Active Roles. These new features bring unmatched flexibility and security to Active Directory environments, supporting customers where they are today and where they want to go in the future. Watch this short video to find out how these features can help streamline and protect your Active Directory.

The best risk management software for enterprises

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.