Tag
medium
advisory
GenAI Tool Configuration Poisoning via MCP Server Injection
1 rule 2 TTPsAdversaries are targeting configuration files of popular GenAI tools to inject malicious Model Context Protocol (MCP) servers, enabling persistence, arbitrary command execution, and data exfiltration.
Cursor +9
defense-evasion
persistence
genai-security
supply-chain
1r
2t
high
advisory
Unauthorized GenAI Tool Access to Sensitive Local System Files
1 rule 2 TTPsAttackers are increasingly leveraging GenAI agent processes to perform unauthorized discovery, harvesting of sensitive credentials, and establishment of persistence via shell configuration modifications.
credential-access
collection
persistence
genai-security
1r
2t