AI Adoption Is Fueling New Security Risks
A senior cybersecurity staffer from a Fortune 500 organization learned something alarming and unexpected during a recent training session at Black Hat USA: Because his company's Model Context Protocol (MCP) server wasn't secured properly, anyone on the conference's public network could have gained write-access to its Endpoint Detection and Response (EDR) system.
"'Somebody on hotel Wi-Fi could have host-isolated all of your endpoints across the entire company,'" James Pope, SOC lead for the Black Hat Network Operations Center, said he told the attendee. "'It also looks like your identity was in there. So, we could have locked out every user in the entire org.'"
The company had apparently set up the MCP gateway and Claude CLI to manage its security stack, which Black Hat NOC analysts could see included CrowdStrike Falcon, Google SecOps, Optiv and Obsidian tools.
Please select this link to read the complete article from techtarget.