Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

MCP Prompt Injection: How Attackers Hijack AI Agent Workflows Through MCP Tool Calls

Prompt injection in a standard LLM interaction produces bad output. The model says something it shouldn’t. The damage stays contained to text. Prompt injection in an MCP environment is a different problem. Agents built on the Model Context Protocol don’t just generate responses. They call tools. They write files, query databases, send emails, execute code, invoke APIs.

CultureAI: In Partnership with Microsoft & NVDIA

CultureAI is a UK-founded AI security and governance platform that enables organisations to adopt AI safely, confidently, and at scale. Sensitive data is flowing into AI tools, SaaS applications with embedded AI, shadow AI, and personal accounts, creating compliance, privacy, and data loss risks that traditional security and governance tools were never built to understand.

Post-quantum authentication to origins is now supported

Cloudflare's Authenticated Origin Pulls and Custom Origin Trust Store now support post-quantum authentication. Here we’ll explain how you can configure fully post-quantum secure mutually authenticated TLS connections to your origin server, dive into the engineering details of how we built it, make a shameful confession, and finally explain how this work fits into our overall post-quantum migration roadmap.

No Hackers Required: 10 Shadow AI Leaks Hiding in Plain Sight

“The call is coming from inside the house.” It’s one of horror’s oldest lines, and you already know how the scene goes. The team scrambles, rechecks every firewall, audits every login, hunting for an intruder. Then the trace comes back, and there isn’t one because there is no malware or forced entry. Just an employee, at their own desk, with their own login, who pasted a confidential spreadsheet into an unapproved AI tool to save 10 minutes before a deadline.

The ECB's AI Cybersecurity Action Plan: Why Speed, Visibility, and Evidence Matter

AI is compressing the cybersecurity timeline faster than most institutions can adapt to it. Not only do security leaders have to deal with this new reality, they have to answer key questions to internal and external audiences about their efforts — including regulators.

The Coding Agent Attack Surface Needs More Than Posture Checks

Coding agents have a misconfiguration problem. YOLO mode enabled to reduce approval friction, sandbox enforcement disabled, Model Context Protocol (MCP) servers installed from public marketplaces without security review. These are common configurations in enterprise developer environments, and remediating them is genuinely valuable work. AI Security Posture Management (AISPM) addresses exactly this class of risk, surfacing misconfigurations before they create the conditions for a successful attack.

Scaling Video Content Without Burning Out

Video has become one of the most effective ways for businesses and creators to reach their audiences. Whether it's educational content, product demonstrations, interviews, podcasts, or behind-the-scenes footage, publishing videos consistently helps build trust and visibility across platforms. However, as the demand for fresh content grows, so does the workload behind every upload.

How Can an IBP Guide Connect Financial and Operational Drivers?

Finance and operations can drift apart even while serving one plan. Revenue goals may depend on capacity, labor, stock, quality, and delivery timing, yet those drivers often sit in separate models. Integrated business planning brings those signals into a shared routine. With clearer links between field activity and financial results, leaders can judge risk earlier, protect cash, and make practical choices before pressure reaches customers.