PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM
CYBERSECURITY
-
Credential Harvester Attack: Rotate All Security Keys Immediately
By
–
If you were impacted, rotate ALL your credentials immediately. The credential harvester in the attack harvested everything from ssh keys, aws keys, gcp keys, azure secrets, kubectl tokens, db configs, crypto wallets, ci/cd secrets, and even shell history.
→ View original post on X — @jiquanngiam, 2026-03-26 03:37 UTC
-
Full post on incident: no prompt injection required
By
–
Full post on the incident: futuresearch.ai/blog/no-prom…
→ View original post on X — @jiquanngiam, 2026-03-26 03:33 UTC
-

Security Alert: Migrate Local MCP Servers to Remote Architecture
By
–
PSA: Stop running local MCP servers. The folks at futuresearch were pwned when a local MCP server pulled in an impacted package. Always run your MCP servers remotely. The blast radius should be limited to the container that it runs in. If you're impacted by the LiteLLM incident and looking for strategies to move to a remote MCP architecture for your company, @MintMCP_AI can help you. DM me.
→ View original post on X — @jiquanngiam, 2026-03-26 03:33 UTC
-
MCP Server Security: Local Execution Risks and Remote Solutions
By
–
We've been recommending all our customers to disallow running local MCP servers. Thank you for highlighting and bringing this problem to light. Our solution makes it easy to run any (even stdio) server remotely. If you're impacted and want a longer term secure solution, please
-
Tech Policy Threatens American Sovereignty and Economic Growth
By
–
I agree that it’s extremely counterproductive and directly undermines American sovereignty as regards both national security and economic growth/prosperity. But, I fear this is just the tip of the iceberg.
-

CCP Trolls Exploit Unrestricted Tweet Replies Online
By
–
When you forget to limit the replies to your tweets and the CCP trolls show up. pic.twitter.com/mKJb0D5ObU
— 🖤 Christine (@christinelu) 25 mars 2026When you forget to limit the replies to your tweets and the CCP trolls show up.
-
AI-Powered Fraud Threats Outpace Organizational Response Capabilities
By
–
Fraudsters don’t have governance committees or budget cycles. They just act. New research by @TheACFE + SAS asks whether organizations can move fast enough to keep up with #deepfakes & other AI-charged #fraud threats. Spoiler: most can’t yet.
-
Cloud CLI Auth Patterns and Command Discovery Suggestions
By
–
great list, maybe also return related commands/suggested next commands on output to nudge discovery auth is a big hole for cloud agents using clis, better design patterns there
-
Claude AI Agent Security Risk: Dangerous Command Validation
By
–
Now @AnthropicAI #Claude #cowork #aiAgent can ask you to validate you want to do rm -rf / and you can say : yes !
