49 Followers
503 Following
139 Posts
white hat hacker | co-founder lutra security | #weAreLutra
Lutrahttps://lutrasecurity.com/team
GitHubhttps://github.com/flintflump

@flintflump asked me for a second opinion on this questionable article by #equixly about MCP security. I don't disagree that MCPs are causing lots of security issues, but the example in the article is just not one of them.

https://equixly.com/blog/2025/03/29/mcp-server-new-security-nightmare/

The supposedly vulnerable code boils down to subprocess.call("notify-send", alert_title), where alert_title is untrusted. As long as notify-send is not vulnerable to RCE, this is completely fine: args is a list and shell is (implicitly) False.

đŸ§” 1/3

MCP Servers: The New Security Nightmare

MCP servers are becoming a colossal remote code execution risk. Why are 2025’s newest AI tools repeating old security mistakes?

Equixly

BINGO TIME! With CVE-2025-58034, Fortinet secures the crown in my Insecurity Appliance Bingo. This is technically a "high" severity vuln, but since it's being actively exploited and has landed a spot on CISA KEV, I'm admitting it.

https://cku.gt/appbingo25

Reaching a bingo took longer than expected, with FortiNet and Ivanti sitting at 5/6 vulns since about July. But now, there is a well-deserved winner.

I'm now taking new vuln class and vendor suggestions for next year's edition.

The positioning of LLM-based AI as a universal knowledge machine implies some pretty dubious epistemic premises, e.g. that the components of new knowledge are already encoded in language, and that the essential method for uncovering that knowledge is statistical.

Maybe no one in the field would explicitly claim those premises, but they're built into how the technology is being pitched to consumers.

We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EU’s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. https://signal.org/blog/pdfs/germany-chat-control.pdf

@arte did your youtube account got hacked? Now playing fake KI Ads for Bitcoin. Don‘t scan the QR!!!

#fake #ai #youtube #cybersecurity

That's 5D-educational chess.

#FuckGenAI #ChatGPT #GenAIsucksCamelDong

In today‘s installment of #BSidesMunich2025 - NEINth Edition, we focus on the cybercrime trend: Fraud-as-a-Service (FaaS). This business model enables cybercriminals to sell ready-made fraud tools and services—from phishing kits to identity theft packages—on dark web marketplaces.

Learn more under the link below!

https://social.bsidesmunich.org/?p=1157

#NixOS 25.11 is Xantusia 🩎 <3

Unsere Kollegen @redpanda und @flintflump hatten diese Woche die Freude, am ec25 Engineering Camp teilzunehmen. Ein großes Dankeschön an #QAware fĂŒr die Einladung und die hervorragende Organisation!

Es waren Tage voller spannender VortrĂ€ge, Workshops und neu gewonnener Erkenntnisse. FĂŒr uns war insbesondere der Einblick, wie LLMs in die Softwareentwicklung Einzug halten, sehr interessant. Wir konnten uns in persönlichen GesprĂ€chen nicht nur ĂŒber die damit verbundenen Chancen, sondern auch intensiv ĂŒber die Risiken austauschen.

Ganz besonders gefreut haben wir uns darĂŒber, dass Stefan Feuerstein die Gelegenheit hatte, zu prĂ€sentieren, wie Unternehmen eine Software Bill of Materials (SBOM) nutzen können, um nicht nur die Anforderungen des Cyber Resilience Act zu erfĂŒllen, sondern auch Bedrohungen in ihrer Supply Chain eigenstĂ€ndig zu erkennen und zu vermeiden.

Und jetzt hĂ€lt der @flintflump wieder einen großartigen Talk ĂŒber SBOMs auf unserem Engineering Camp đŸ€©

@lutrasecurity #EngineeringCamp #QAware #SBOM #infosec #security