Skip to main content
Logo-300x300-colored-3
  • Home
  • Services
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • AI Advisory
    • AI Assessment
    • AI Integration
  • Products
  • About
    • About Us
    • FAQ's
  • Resources
    • Blog
    • In The Media
    • Podcasts
    • All Resources
Get a Free Assessment
Back to Blog
Prompt Injection AI Security Supply Chain Developer Tools Appsec MCP

973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security

Jacob Krell June 17, 2026 9 min read
Table of Contents

    At a Glance

    • AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. Download ratios: 10:1 on PyPI, 28:1 on npm.

    • AI-generated code ships vulnerable at baseline. 45% failure rate across 150+ LLMs. 55.8% provable vulnerability rate in formal verification across 7 models. No model scored better than a D.

    • The MCP ecosystem has early-npm-era supply chain maturity. 973 packages on npm, 71% single-maintainer, 56% published in the last 30 days, 25% with no source repo. 9 of 11 MCP registries failed to detect malicious uploads.

    • MCP config files are a credential exposure vector. 24,008 secrets found on public GitHub, 2,117 confirmed live.The WAVESHAPER campaign proved attackers already enumerate these files.

    • Prompt injection is accelerating through the CVE pipeline. 133 CVEs in NVD, 78% rated CRITICAL or HIGH. The pace went from 3 in 2023 to 51 in 2025, with every major AI coding tool affected.

    For every security tool download on npm, there are 28 AI coding tool downloads. On PyPI, the ratio is 10:1. Ninety percent of developers now use AI coding tools at work, and the security tooling for those workflows is not scaling at the same rate.

    Three attack surfaces account for most of the risk: the code AI generates, the credentials developers feed it, and the context window itself. Each has specific, deployable controls. Most teams have implemented none of them.

    adoption_vs_governance_gap

    The Code AI Writes

    The most discussed risk is the most measurable. Veracode's Spring 2026 GenAI Code Security Report tested over 150 LLMs across security-sensitive coding tasks. 45% of AI-generated code contained known security vulnerabilities. That number has not improved since their first 2025 report.

    Cross-site scripting failures hit 86%. Log injection hit 88%. These are OWASP Top 10 staples, not edge cases.

    A formal verification study published in April 2026 put the number higher: 55.8% of artifacts contained at least one provable vulnerability. GPT-4o scored worst at 62.4%. Gemini 2.5 Flash scored best at 48.4%. No model achieved better than a D grade.

    Models identify their own vulnerable outputs 78.7% of the time when asked to review. They still generate those same flaws at 55.8% by default. The generation-review asymmetry means code review by the same model that wrote the code catches less than you would expect.

    The Controls:

    Run SAST on every commit, not just at PR time. With 41% of commercial code now AI-generated, scan-on-merge is too late. Tools like Semgrep, CodeQL, and Snyk integrate directly into IDE workflows and CI pipelines. The goal is catching the 45% before it reaches a branch, not after it reaches production.

    Treat AI output the way you treat third-party library code: untrusted by default. Code review processes should flag AI-generated changes for security-focused review, particularly for auth logic, cryptographic implementations, and input handling. The Armis Trusted Vibing Benchmark found universal blind spots across all 18 models tested: memory buffer overflows, file upload handling, login systems, and deserialization all failed 100% of the time.

    The MCP Supply Chain and Credential Exposure

    The npm registry now contains 973 packages with "mcp" in the name. 71% have a single maintainer. 56% were published in the last 30 days. 25% have no linked source repository.

    Average package age: 98 days. This ecosystem went from zero to nearly a thousand packages in under 18 months, and more than half of it materialized in the last month alone.

    mcp_ecosystem_maturity

    Every one of those packages can execute operating system commands when installed as an MCP server. The STDIO transport, which is the default, passes configuration parameters directly into OS command execution without validation. Anthropic has called this expected behavior. OX Security tested 11 major MCP registries and found that 9 accepted malicious server uploads without detection.

    MCP config files store API keys, database credentials, and OAuth tokens in plaintext JSON. GitGuardian's 2026 State of Secrets Sprawl report found 24,008 unique secrets in MCP config files on public GitHub. 2,117 were confirmed live at the time of scanning.

    Commits co-authored by AI coding tools leaked secrets at twice the baseline rate across all of public GitHub. 28.6 million total secrets were detected on GitHub in 2025, a 34% year-over-year increase.

    mcp_attack_surface

    On March 31, 2026, the North Korean group UNC1069 hijacked the real `axios` npm package and deployed the WAVESHAPER.V2 backdoor to developer machines across Windows, macOS, and Linux . Lorikeet Security's analysis of the campaign found that the malware enumerated MCP configuration files for Claude Code, Cursor, Windsurf, and VS Code Continue, injecting rogue server definitions that turned the AI assistant into an exfiltration channel.

    How to lock this down:

    Never store plaintext credentials in MCP config files. Use environment variable references (`env:` blocks) or vault-based injection via 1Password CLI, HashiCorp Vault, or AWS Secrets Manager. The config file should contain a reference, never the secret.

    Add `.cursor/mcp.json`, `.claude.json`, `claude_desktop_config.json`, and `.mcp.json` to your `.gitignore`. Enable GitHub Secret Scanning and Push Protection on every repository. GitHub's MCP Server has supported secret scanning since March 2026.

    Audit developer machines for unexpected MCP server entries. The WAVESHAPER campaign proved that attackers target these files specifically. If a developer cannot explain why a server entry exists, remove it.

    Pin MCP server packages to specific versions and audit before upgrading. With 71% of MCP packages maintained by a single person and over half the ecosystem less than 30 days old, the supply chain maturity of this ecosystem resembles early npm circa 2015. Treat new MCP server installations the way you would treat a new third-party dependency: review the source, check the maintainer, and scope its permissions.

    The Context Window as Attack Surface

    Prompt injection against AI coding assistants has moved from research papers to production CVEs. The NVD now contains 133 CVEs mentioning "prompt injection," with 78% rated CRITICAL or HIGH. The year-over-year acceleration is steep: 3 CVEs in 2023, 19 in 2024, 51 in 2025, and 16 in the first five months of 2026.

    prompt_injection_cves_by_year

    Every major AI coding tool has been hit:

    Tool CVE CVSS Attack Vector
    GitHub Copilot CVE-2025-53773 7.8 Malicious code comments modify VS Code settings, bypass approval, achieve RCE
    Cursor IDE CVE-2026-22708 9.8 Shell built-in bypass (part of a 3-CVE chain with git hook escape + TOCTOU race)
    Claude Code CVE-2025-55284 — DNS exfiltration encoding stolen data in subdomain lookups
    Cursor IDE CVE-2025-54135 9.8 Indirect prompt injection in repo files creates malicious .cursor/mcp.json, achieves RCE
    AWS Kiro — — Poisoned spec files trigger code generation and execution without user request
    Google Jules — — Unrestricted outbound connectivity allows full credential harvesting

    The attack pattern across all of these is the same. An attacker embeds hidden instructions in content the AI processes automatically: a README, a GitHub issue, a code comment, a dependency's documentation. The AI reads it, follows the instructions, and acts using whatever permissions the developer granted. Industry audit data widely cited by OWASP practitioners puts the rate at 73% of production AI deployments containing prompt injection vulnerabilities.

    Reducing the blast radius:

    Restrict AI agent permissions to the minimum needed. If the assistant does not need shell access for a task, disable it. Cursor, Claude Code, and Copilot all have configuration options to limit tool access. Review which tools and capabilities your AI assistant has enabled, and disable anything not actively required.

    Be cautious with untrusted repositories. Opening a cloned repo in an AI-enabled IDE is now an attack vector. The CurXecute vulnerability (CVE-2025-54135, CVSS 9.8) allowed arbitrary command execution when the AI processed content from a poisoned repository. Treat unfamiliar repositories the way you treat unfamiliar email attachments: open in a sandboxed environment first.

    Keep AI tools updated. The CVE cadence for coding assistants now rivals that of web browsers. Cursor, Copilot, and Claude Code have all shipped critical patches in 2026. Auto-update where possible, and build update checks into your regular patching cycle.

    Use context restriction files. Cursor supports `.cursorignore` to exclude sensitive files and directories from AI context (indexing, tab completion, agent reads). One caveat: terminal commands run by the agent can bypass `.cursorignore`, so pair it with restrictive auto-run settings. For sensitive projects, add `.env`, credentials files, and key material to `.cursorignore` as a baseline. Claude Code supports `.claude/settings.json` with `deny` patterns for similar per-project restrictions.

    Monitor outbound traffic from IDE processes. The Claude Code DNS exfiltration attack (CVE-2025-55284) worked because DNS lookups from a coding tool look like normal name resolution. Network monitoring that baselines IDE process behavior and flags anomalous destinations is the detection layer most teams are missing. EDR tools that track process-level DNS activity can catch this if configured to watch IDE binaries.

    What Comes Next

    AI coding assistants are gaining the ability to create branches, open PRs, deploy to staging, and access production databases. Each new capability is a permission that prompt injection can hijack. The 133 prompt injection CVEs filed so far are the early returns on an expanding attack surface.

    Security teams that wait for vendors to solve this will be waiting through the vulnerability curve. The controls in this guide work with tools available today. The gap between AI adoption and AI security governance is 10:1 on PyPI and 28:1 on npm. Closing it starts with treating AI developer tooling as attack surface.


    Sources

    • JetBrains AI Pulse Survey, January 2026

    • Stack Overflow Developer Survey 2025 (n=49,000+)

    • Veracode, "Spring 2026 GenAI Code Security Update" (2026)

    • "Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code," arXiv:2604.05292 (April 2026)

    • Armis Labs, "Trusted Vibing Benchmark" (2026)

    • GitGuardian, "State of Secrets Sprawl 2026" (April 2026)

    • OX Security, MCP STDIO RCE disclosure (April 2026)

    • Cloud Security Alliance, "MCP Design-Level RCE: Protocol Architecture as Attack Surface" (2026)

    • Cloud Security Alliance, "Promptware: When Prompt Injection Becomes C2" (April 2026)

    • Google Threat Intelligence Group, "North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack" (March 2026)

    • Lorikeet Security, "MCP Is the New Supply Chain: 30 CVEs, a North Korean npm Hijack, and 7,000 Exposed Servers" (2026)

    • GitClear, AI Code Analysis (2025-2026)

    • Orca Security, "RoguePilot: Critical GitHub Copilot Vulnerability Exploit" (2026)

    • NVD API (services.nvd.nist.gov), queried June 10, 2026

    • PyPI Stats API (pypistats.org), queried June 10, 2026

    • npm Registry API (api.npmjs.org), queried June 10, 2026

    Share
    Tags: Prompt Injection AI Security Supply Chain Developer Tools Appsec MCP
    Jacob Krell
    Jacob Krell

    Jacob Krell builds systems that are hard to break and breaks systems that appear resilient. He is an offensive security leader specializing in advanced penetration testing and red teaming across cloud, web, mobile, Active Directory, and AI-enabled environments, helping organizations expose real-world risk and validate their defenses against modern adversaries. In parallel, he is a full-stack software engineer who develops custom cybersecurity tooling, intelligent automation platforms, and production-grade applications that embed security directly into the technology lifecycle. Ranked 25th globally on Hack The Box with more than 1,000 flags captured and holding many elite certifications, including OSCE3, CISSP, OSCP, CCNP Security, and CSIE, Jacob combines hands-on technical depth with the ability to translate complex cyber risk into clear business strategy.

    Stay ahead of the threat landscape

    AI security insights, threat intelligence, and research from our team. No spam, unsubscribe anytime.

    Subscribe
    ← Previous The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It

    Latest Posts

    View All
    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    Prompt Injection
    Jun 17, 2026 Jacob Krell

    973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security

    At a Glance AI security tooling adoption lags behind AI coding tool adoption by an order of magnitude. Download ratios: ...

    Read More: 973 MCP Packages, 71% Single-Maintainer: A Practitioner's Guide to AI Developer Security
    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    AI Governance
    May 28, 2026 Jacob Krell

    The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It

    On May 20, 2026, Verizon published the 2026 Data Breach Investigations Report with a dedicated AI section built on ...

    Read More: The AI Governance Gap: Verizon's 2026 DBIR Shows Attackers Scaling AI While Employees Leak Data Through It
    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    Mean Time to Exploit
    May 21, 2026 Jacob Krell

    The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower

    On May 20, 2026, Verizon published the [2026 Data Breach Investigations ...

    Read More: The Remediation Paradox: Verizon's 2026 DBIR Shows Exploitation Winning While Defenders Patch Slower
    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    Cybersecurity
    May 20, 2026 Jacob Krell

    The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code

    GitHub's 3,800 Repositories Stolen Through a Single IDE Extension On May 19, 2026, a single VS Code extension on a ...

    Read More: The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub's Source Code
    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    May 20, 2026 Hannah Perez

    The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability

    If you think a basic pop-up banner that reads "By continuing to browse this site, you accept cookies" protects your ...

    Read More: The Cost of a Click: Why Passive Cookie Consent Is Your Biggest Compliance Liability
    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Data Privacy
    May 19, 2026 Jacob Krell

    Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore

    In April 2026 alone, the ShinyHunters extortion group breached ADT (5.5 million customers), Amtrak (2.1 million ...

    Read More: Five Years of US Privacy Breach Data Tell a Story Security Leaders Cannot Ignore
    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    Vulnerability Management
    May 05, 2026 Jacob Krell

    Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.

    Mandiant's M-Trends 2026 report puts estimated mean time to exploit at negative seven days. That number should reset ...

    Read More: Mean Time to Exploit Has Gone Negative. Security Strategy Has to Change.
    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    Prompt Injection
    Apr 30, 2026 Hannah Perez

    When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance

    When AI Billing Breaks Trust: Lessons from the Claude Code Backlash AI adoption is accelerating, but trust is still ...

    Read More: When AI Billing Breaks Trust: What the Claude Code Backlash Says About AI Governance
    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    Cybersecurity
    Apr 29, 2026 Suzu Labs

    From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield

    Cybersecurity doesn’t start with tools, it starts with mindset. In this episode featuring Aaron Colclough, we get a ...

    Read More: From Army Ranger to Ethical Hacker: What Cybersecurity Can Learn from the Battlefield
    When Elite Cyber Teams Can't Crack Web Security
    Cybersecurity
    Apr 23, 2026 Jacob Krell

    When Elite Cyber Teams Can't Crack Web Security

    HTB's 2025 benchmark tested 796 security teams. Only 21% passed web security challenges. The Security Illusion Security ...

    Read More: When Elite Cyber Teams Can't Crack Web Security
    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Cybersecurity
    Apr 22, 2026 Jacob Krell

    The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them

    In today's security landscape, some of the most dangerous vulnerabilities aren't flagged by automated scanners at all. ...

    Read More: The Invisible Threat: Business Logic Flaws in Modern Applications and Why Scanners Miss Them
    Suzu Labs Acquires Emulated Criminals
    Apr 20, 2026 Hannah Perez

    Suzu Labs Acquires Emulated Criminals

    Bridging the gap between theory and the threat reality, Suzu Labs is proud to announce the acquisition of Emulated ...

    Read More: Suzu Labs Acquires Emulated Criminals
    The Wall Around Claude 4.7 Does Not Extend to Dread
    Cybersecurity
    Apr 17, 2026 Suzu Labs

    The Wall Around Claude 4.7 Does Not Extend to Dread

    Anthropic released Claude Opus 4.7 on April 16, 2026 with automated cybersecurity safeguards and a Cyber Verification ...

    Read More: The Wall Around Claude 4.7 Does Not Extend to Dread
    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    youtube
    Apr 10, 2026 Jacob Krell

    The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control

    Earlier this year, YouTube began rolling out a row of algorithmically recommended videos at the top of the ...

    Read More: The Engagement Ratchet: How YouTube, Instagram, and Amazon Trained Users to Accept Less Control
    The AI Revolution: How Jobs Will Change by 2030
    Cybersecurity
    Apr 07, 2026 Suzu Labs

    The AI Revolution: How Jobs Will Change by 2030

    Host Phillip Wylie sits down with Nicolas Chaillan to discuss the sobering reality of AI replacement, the critical need ...

    Read More: The AI Revolution: How Jobs Will Change by 2030
    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    Generative AI
    Apr 01, 2026 Hannah Perez

    The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?

    In late 2024, Sydney tech entrepreneur Paul Conyngham was told his rescue dog, Rosie, had months to live. She was ...

    Read More: The Rosie Protocol: Is AI-Driven Personalized Medicine Finally Here?
    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    Cybersecurity
    Mar 30, 2026 Suzu Labs

    From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone

    The world of cybersecurity has undergone a massive transformation in just a few decades. In this episode of Simply ...

    Read More: From Analog Hacks to Agentic AI: The Evolution of Offensive Security with Denis Calderone
    While TSA Made Headlines, CISA Went Dark
    Critical Infrastructure
    Mar 30, 2026 Jacob Krell

    While TSA Made Headlines, CISA Went Dark

    The Department of Homeland Security has been partially shut down for over 45 days. In that time, 460 TSA officers have ...

    Read More: While TSA Made Headlines, CISA Went Dark
    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    AI Security
    Mar 30, 2026 Suzu Labs

    The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks

    In cybersecurity, we often operate in silos. The red team breaks things, the blue team fixes them, and management ...

    Read More: The Purple Team Advantage: Bridging the Gap Between Hacking and Management with Chris Marks
    Claude Mythos and the Cybersecurity Risk That Was Already Here
    Threat Intelligence
    Mar 27, 2026 Jacob Krell

    Claude Mythos and the Cybersecurity Risk That Was Already Here

    On March 26, Anthropic confirmed the existence of Claude Mythos, an unreleased AI model described internally as "a step ...

    Read More: Claude Mythos and the Cybersecurity Risk That Was Already Here
    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Critical Infrastructure
    Mar 26, 2026 Mike Bell

    BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It

    Rapid7's research reveals China-linked kernel implants deep inside telecom signaling infrastructure. Here's what ...

    Read More: BPFdoor in Telecom Networks: The FCC Is Securing the Edge, but China's Hackers Are Already Past It
    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    Cybersecurity
    Mar 23, 2026 Hannah Perez

    Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026

    We are incredibly proud to announce a monumental achievement. At this year’s Global InfoSec Awards 2026, hosted by ...

    Read More: Securing the AI Frontier: Suzu Labs Sweeps 4 Global InfoSec Awards 2026
    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Cybersecurity
    Mar 17, 2026 Suzu Labs

    From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity

    In the world of cybersecurity, we often talk about "gatekeeping" or the "skills gap," but rarely do we find individuals ...

    Read More: From Cockpits to Code: Josh Mason on Bridging the Gap Between Military and Cybersecurity
    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    Cybersecurity
    Mar 16, 2026 Phillip Wylie

    Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss

    The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss In this episode of Simply Offensive, ...

    Read More: Simply Offensive Podcast: The Future of Pentesting: AI, Automation, and Better Reporting with Dan DeCloss
    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Critical Infrastructure
    Mar 13, 2026 Denis Calderone

    From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time

    On March 12, medical technology giant Stryker confirmed a cyberattack that wiped devices across 79 countries. The ...

    Read More: From Silence to Strike: Tracking Iran's Cyber Escalation in Real Time
    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    Social Engineering
    Mar 09, 2026 Suzu Labs Intelligence

    Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation

    Executive Summary Even Realities markets its G2 smart glasses as the privacy-conscious alternative to Meta Ray-Bans. ...

    Read More: Internal Analysis: Even Realities G2 Smart Glasses Security & Privacy Investigation
    The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    Threat Intelligence
    Mar 06, 2026 Mike Bell

    The Company Reviewing Your Meta Glasses Footage Has a Security Problem

    Last week, Swedish journalists revealed that Meta sends video footage from Meta Ray-Ban smart glasses to human data ...

    Read More: The Company Reviewing Your Meta Glasses Footage Has a Security Problem
    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    CTF
    Mar 03, 2026 Jacob Krell

    The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

    View White Paper Abstract: Agentic AI systems are compressing competitive hacking timelines faster than the ...

    Read More: The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Cybersecurity
    Mar 03, 2026 Phillip Wylie

    Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell

    In this thought-provoking episode of Simply Offensive, host Philip Wylie sits down with Jacob Krell, a penetration ...

    Read More: Simply Offensive Podcast: AI Killed the CTF Star with Jacob Krell
    Anthropic and Claude: 2026 AI Powerhouse
    Supply Chain Security
    Feb 26, 2026 Hannah Perez

    Anthropic and Claude: 2026 AI Powerhouse

    In early 2026, the image of Anthropic as a cautious, safety-oriented "research lab" has effectively been replaced by ...

    Read More: Anthropic and Claude: 2026 AI Powerhouse
    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Cybersecurity
    Feb 24, 2026 Phillip Wylie

    Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle

    In this episode of Simply Offensive, host Philip Wylie welcomes Darius Houle, an Application Security (AppSec) and ...

    Read More: Simply Offensive Podcast: Navigating AI's Challenges in Problem Solving with Darius Houle
    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Cybersecurity
    Feb 17, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown

    In the latest episode of the Simply Offensive podcast, host Philip Wylie sat down with Matt Brown, a renowned hardware ...

    Read More: Simply Offensive Podcast: Exploring the World of Hardware Hacking with Matt Brown
    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Cybersecurity
    Feb 12, 2026 Phillip Wylie

    Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs

    In today’s rapidly evolving technological landscape, the convergence of artificial intelligence (AI) and cybersecurity ...

    Read More: Simply Offensive Podcast: Exploring AI Vulnerabilities in Cybersecurity with Mike Bell of Suzu Labs
    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Threat Intelligence
    Feb 10, 2026 Phillip Wylie

    Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss

    Beyond the Pentest: Why Adversarial Emulation is the Future of Defensive Training Many organizations operate under the ...

    Read More: Simply Offensive Podcast: Emulated Cyber Crime with Dahvid Schloss
    Under Armour Breach: What The Forum Data Actually Shows
    Threat Intelligence
    Jan 30, 2026 Mike Bell

    Under Armour Breach: What The Forum Data Actually Shows

    On January 18, 2026, the Everest ransomware group made good on their threat and released Under Armour customer data to ...

    Read More: Under Armour Breach: What The Forum Data Actually Shows
    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Briefing Room
    Jan 29, 2026 Dahvid Schloss

    SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers

    This article is in reference to our newest POC hosted on GitHub here: https://github.com/Emulated-Criminals/SilentFrame ...

    Read More: SilentFrame: A Research POC on Post-Exploitation Credential Collection through Browsers
    Brightspeed Breach: Crimson Collective and the Infostealer Problem
    Threat Intelligence
    Jan 20, 2026 Mike Bell

    Brightspeed Breach: Crimson Collective and the Infostealer Problem

    Recently Crimson Collective claimed they breached Brightspeed and grabbed 1 million+ customer records. The list of data ...

    Read More: Brightspeed Breach: Crimson Collective and the Infostealer Problem
    When Grid Data Goes Dark Web
    Power Grid
    Jan 19, 2026 Mike Bell

    When Grid Data Goes Dark Web

    Inside a threat actor's critical infrastructure targeting In January 2026, 139 gigabytes of engineering data from a ...

    Read More: When Grid Data Goes Dark Web
    The $150,000 Password
    Critical Infrastructure
    Jan 19, 2026 Mike Bell

    The $150,000 Password

    How one threat actor turned stolen credentials into a global breach portfolio Between December 2025 and January 2026, a ...

    Read More: The $150,000 Password
    Seeing Everything, Understanding Nothing
    Briefing Room
    Jan 16, 2026 Dahvid Schloss

    Seeing Everything, Understanding Nothing

    To help you get a head start on making your environment safer and in keeping with the theme of January’s “New Year, New ...

    Read More: Seeing Everything, Understanding Nothing
    New Year, New Priorities - So, what to fix first?
    Briefing Room
    Jan 08, 2026 Dahvid Schloss

    New Year, New Priorities - So, what to fix first?

    The most common phrase we hear from our prospects is, “We are overwhelmed, and we aren’t sure what to tackle first.” ...

    Read More: New Year, New Priorities - So, what to fix first?
    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Briefing Room
    Nov 21, 2025 Dahvid Schloss

    UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)

    Repository purpose: this research was to evaluate the feasiabilty of using Alternate Data Stream (ADS) in staging and ...

    Read More: UnderByte — A Ransomware experiment using Alternate Data Streams (ADS)
    Logo copy 3-1

    Fortified Security. Intelligent Innovation.

    +1 (702) 766-6257
    P.O. Box 750111
    Las Vegas, Nevada 89136

    Follow Us

    About

    • About Us
    • Contact
    • FAQ's

    Solutions

    • AI Advisory
    • AI Assessment
    • Offensive Security
    • Defensive Security
    • Privacy Engineering
    • Adversarial Operations
    • Social Engineering
    • Products

    Resources

    • Blog
    • In The Media
    • Podcasts
    © 2026 All rights reserved.
    • Privacy Policy
    • Terms & Conditions