INS Security Blog
Deep dives into MCP security, AI agent threats, detection strategies, and best practices for protecting your AI infrastructure.
Anthropic MCP STDIO RCE: 11 CVEs, 150M Downloads, and the Case for External Gateways
A systemic flaw in Anthropic's MCP STDIO transport exposes 200,000+ AI servers. Anthropic declined to patch the protocol. Here is what to do now.
Setting Up an MCP Security Gateway: Architecture and Deployment Guide
Architecture overview, deployment patterns, configuration, and policy setup for securing your MCP infrastructure.
AI Agent Security Best Practices for 2026
Comprehensive guide covering least privilege, input validation, output scanning, session management, and monitoring for AI agents.
How to Audit AI Agent Tool Calls: A Complete Guide
Why audit trails matter, what to log, session correlation, and compliance requirements for SOC 2 and GDPR.
Data Exfiltration Through AI Agents: Attack Vectors and Defenses
How attackers use AI agents to extract sensitive data across multiple tool calls and how to detect multi-step exfiltration chains.
OWASP LLM Top 10 (2025): A Practical Compliance Guide for AI Teams
Walk through each of the OWASP LLM Top 10 items, understand the risks, and learn practical mitigation strategies.
MCP Proxy vs API Gateway: Which One Secures Your AI Agents?
Compare traditional API gateways with MCP-aware proxies. What works, what doesn't, and why MCP needs specialized security.
How to Prevent PII Leaks in AI Agent Workflows
Types of PII exposure in MCP workflows, detection approaches, masking strategies, and compliance implications.
Rug Pull Attacks on MCP Tools: The Silent Threat to AI Agent Security
How tool descriptions can be silently modified after approval, and why SHA-256 hashing is essential for detection.
MCP Tool Poisoning Attacks: How Malicious Tool Descriptions Compromise AI Agents
Deep dive into tool poisoning attack vectors, real examples of malicious tool descriptions, and detection methods.
What Is MCP Security? A Complete Guide to Securing Model Context Protocol
Everything you need to know about MCP, its attack surfaces, and how to protect your AI agent infrastructure.