Black Hat NOC sees AI security failures firsthand | TechTarget
A senior cybersecurity staffer from a Fortune 500 organization learned something alarming and unexpected during a recent training session at Black Hat USA: Because his company's MCP server wasn't secured properly, anyone on the conference's public network could have gained write-access to its EDR system.
"'Somebody on hotel Wi-Fi could have host-isolated all of your endpoints across the entire company,'" James Pope, SOC lead for the Black Hat Network Operations Center, said he told the attendee. "'It also looks like your identity was in there. So, we could have locked out every user in the entire org.'"
The company had apparently set up the MCP gateway and Claude CLI to manage its security stack, which Black Hat NOC analysts could see included CrowdStrike Falcon, Google SecOps, Optiv and Obsidian tools.
"They were passing their token in the clear," said Bart Stump, managing principal at Coalfire, during a conference session...
Copyright of this story solely belongs to techtarget.com. To see the full text click HERE