Alfredo Oliveira
12 articles
-
BlogHow TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow
TrendAI™ Research uncovered an open redirect in Dify's post-login flow that could have handed a freshly authenticated session, token and all, to an attacker, and worked with the vendor to close it across every sign-in path before the details went public.
August 4th, 2026David Fiser, Alfredo Oliveira
Read article -
ResearchStars Don’t Save You: Popularity Is Not Security in the MCP Ecosystem
Building on our previous research, we correlated the security issues identified in public MCP servers with metadata crawled from popular directories. We then analyzed whether indicators such as popularity, activity, and vetting serve as reliable metrics to infer the risk of adopting an MCP server.
June 24th, 2026Vincenzo Ciancaglini, Marco Balduzzi, Alfredo Oliveira, David Fiser
Read article -
ResearchHunt Them All: An AI-Powered Vulnerability Sweep of 19,000 MCP Servers
In this research, we analyzed over 19,000 open-source MCP server repositories to uncover how much AI-generated code they contain and how many harbor exploitable vulnerabilities.
May 27th, 2026Alfredo Oliveira , David Fiser
Read article -
ResearchUpdate on Exposed MCP Servers: The Threat Widens to the Cloud
Blurb: Exposed Model Context Protocol (MCP) servers have become powerful vectors for cloud attacks, enabling threat actors to not only access sensitive data but also take control of the cloud services themselves.
April 28th, 2026Alfredo Oliveira , David Fiser
Read article -
Blog駭客濫用惡意 OpenClaw Skills,散布 Atomic macOS Stealer 竊密軟體
惡意的 OpenClaw 技能會誘騙 AI 代理和使用者安裝新的 AMOS 變種來竊取大量資料。
February 23rd, 2026 8 minAlfredo Oliveira, Buddy Tancio, David Fiser, Philippe Lin…
Read article -
ResearchUsing Containers to Secure Your MCP Infrastructure
Security risks to MCP servers can be mitigated by running them within containers. This report discusses these security risks and how MCP containerization can implement least privilege in practice.
September 17th, 2025 14 minAlfredo Oliveira , David Fiser
Read article -
ResearchBeware of MCP Hardcoded Credentials: A Perfect Target for Threat Actors
Poor secret management in MCP servers can lead to serious consequences, including data breaches and supply chain attacks. This article examines the reality of these unsecure configurations and offers practical recommendations that minimize the chances of exposure.
August 13th, 2025 7 minAlfredo Oliveira , David Fiser
Read article -
ResearchMCP Security: Network-Exposed Servers Are Backdoors to Your Private Data
Exposed MCP servers pose a risk for organizations utilizing them. Our research examined the types of concerns that emerge and how to keep systems safe through immediate and extended measures.
July 16th, 2025Alfredo Oliveira , David Fiser
Read article -
ResearchSilent Sabotage: Weaponizing AI Models in Exposed Containers
How can misconfigurations help threat actors abuse AI to launch hard-to-detect attacks with massive impact? We reveal how AI models stored in exposed container registries could be tampered with— and how organizations can protect their systems.
December 4th, 2024 14 minAlfredo Oliveira , David Fiser
Read article -
ResearchToday’s Cloud and Container Misconfigurations Are Tomorrow’s Critical Vulnerabilities
It’s projected that by 2027, more than 90% of global organizations will be running containerized applications, while 63% of enterprises already adopted a cloud-native strategy in their businesses in 2023.
August 6th, 2024 16 minAlfredo Oliveira
Read article -
ResearchKong API Gateway Misconfigurations: An API Gateway Security Case Study
Tools that aggregate access into multiple different environments, such as API gateways, pose a security risk for all these environments upon breach. In this article, we continue our journey through the security issues of the API Gateway landscape. Our new research focuses on another popular API gateway — Kong.
May 21st, 2024 11 minAlfredo Oliveira , David Fiser
Read article -
ResearchThreat Modeling API Gateways: A New Target for Threat Actors?
In this article, we dive into API gateway functions and risks, the advantages of API gateways in hybrid and multi-cloud environments, and common API security risks and best practices.
December 14th, 2023 7 minDavid Fiser, Alfredo Oliveira
Read article