David Fiser
12 articles
-
BlogDifyのログイン後フローに存在したオープンリダイレクト脆弱性:TrendAI™ Researchによる発見から修正まで
TrendAI™ Researchは、認証直後のセッションをトークンごと攻撃者に渡してしまうおそれのあるオープンリダイレクト脆弱性をDifyのログイン後フローに発見し、詳細の公開に先立ち、ベンダーと連携してすべてのサインイン経路で修正を完了させました。
August 4th, 2026David Fiser, Alfredo Oliveira
Read article -
Researchスターの数では守れない:MCPエコシステムにおいて人気は安全性の証にはならない
本リサーチでは、これまでの研究を踏まえ、公開されているMCPサーバで確認されたセキュリティ問題を、主要なディレクトリからクロールしたメタデータと突き合わせて分析しました。そのうえで、人気度・活動状況・審査の有無といった指標が、MCPサーバを採用する際のリスクを推し量る信頼できる尺度となり得るかを検証しました。
June 24th, 2026Vincenzo Ciancaglini, Marco Balduzzi, Alfredo Oliveira, David Fiser
Read article -
Research一網打尽:AIで挑む19,000台のMCPサーバ脆弱性調査
本リサーチでは、19,000を超えるオープンソースのMCPサーバリポジトリを分析し、それらにどれほどAI生成コードが含まれているか、また悪用可能な脆弱性をどれほど抱えているかを明らかにしました。
May 27th, 2026Alfredo Oliveira , David Fiser
Read article -
Research外部公開された MCP サーバの最新動向:脅威はクラウドへと拡大
外部公開された Model Context Protocol(MCP)サーバは、クラウド攻撃の強力な経路と化しています。攻撃者は機密データにアクセスできるだけでなく、クラウドサービスそのものを掌握することも可能になっています。
April 28th, 2026Alfredo Oliveira , David Fiser
Read article -
BlogOpenClawの不正なスキルを通してmacOS型情報窃取ツール「AMOS」が拡散
不正なOpenClawのスキルによってAIエージェントを欺き、macOS版情報窃取ツール「AMOS」の新型亜種を拡散させる攻撃が発生しています。本稿では、その手口と対策を解説します。
February 23rd, 2026 8 minAlfredo Oliveira, Buddy Tancio, David Fiser, Philippe Lin…
Read article -
ResearchUsing Containers to Secure Your MCP Infrastructure
Security risks to MCP servers can be mitigated by running them within containers. This report discusses these security risks and how MCP containerization can implement least privilege in practice.
September 17th, 2025 14 minAlfredo Oliveira , David Fiser
Read article -
ResearchBeware of MCP Hardcoded Credentials: A Perfect Target for Threat Actors
Poor secret management in MCP servers can lead to serious consequences, including data breaches and supply chain attacks. This article examines the reality of these unsecure configurations and offers practical recommendations that minimize the chances of exposure.
August 13th, 2025 7 minAlfredo Oliveira , David Fiser
Read article -
ResearchMCP Security: Network-Exposed Servers Are Backdoors to Your Private Data
Exposed MCP servers pose a risk for organizations utilizing them. Our research examined the types of concerns that emerge and how to keep systems safe through immediate and extended measures.
July 16th, 2025Alfredo Oliveira , David Fiser
Read article -
ResearchSilent Sabotage: Weaponizing AI Models in Exposed Containers
How can misconfigurations help threat actors abuse AI to launch hard-to-detect attacks with massive impact? We reveal how AI models stored in exposed container registries could be tampered with— and how organizations can protect their systems.
December 4th, 2024 14 minAlfredo Oliveira , David Fiser
Read article -
ResearchKong API Gateway Misconfigurations: An API Gateway Security Case Study
Tools that aggregate access into multiple different environments, such as API gateways, pose a security risk for all these environments upon breach. In this article, we continue our journey through the security issues of the API Gateway landscape. Our new research focuses on another popular API gateway — Kong.
May 21st, 2024 11 minAlfredo Oliveira , David Fiser
Read article -
ResearchThreat Modeling API Gateways: A New Target for Threat Actors?
In this article, we dive into API gateway functions and risks, the advantages of API gateways in hybrid and multi-cloud environments, and common API security risks and best practices.
December 14th, 2023 7 minDavid Fiser, Alfredo Oliveira
Read article -
ResearchInfrastructure as Code: Security Risks and How to Avoid Them
Infrastructure as Code (IaC) is a key DevOps practice that bolsters agile software development. In this report, we identify security risk areas in IaC implementations and the best practices in securing them in hybrid cloud environments.
July 14th, 2020 8 minDavid Fiser
Read article