Founder & CEO of Jutsu | Building AI-Native Security Operations for Startups | OrangeDAO W24 | HBS Foundry
- ๐จ Most people donโt understand OSINTโฆ but attackers do. ๐๐๐๐๐ (๐๐ฉ๐๐ง ๐๐จ๐ฎ๐ซ๐๐ ๐๐ง๐ญ๐๐ฅ๐ฅ๐ข๐ ๐๐ง๐๐) is the process of collecting and analyzing publicly available data to uncover insights about people, systems, or organizations. No hacking required. Just better
- AI agents are becoming the new browsers and MCP is the new attack surface. Iโm writing a book on MCP Security because almost no one is thinking about how dangerous over-privileged MCP servers + prompt injection can become. If your agents can touch: โข Filesystems โข Email โข
- MCP is becoming the โUSB-C for AI agentsโโฆ and a massive new attack surface. The biggest MCP security risks you should know: โข Fake/malicious MCP servers (e.g., โpostmark-mcpโ stealing emails) โข Over-privileged tools: FS access, shell, prod DB โข Prompt-injection via
- Architecting secure enterprise AI agents with MCP MCP is becoming the standard way to connect AI agents to tools, APIs, and internal systems โ but itโs also becoming a high-value attack surface. Recent incidents show why: - A malicious MCP server on npm quietly exfiltrated

