Chinese hackers breach 700 companies through single Salesforce integration

16 speckx 1 9/2/2025, 7:59:47 PM nearlyright.com ↗

Comments (1)

electric_muse · 5h ago
Wait until the next big MCP supply chain fiasco.

Most CISOs are intentionally turning a blind eye to MCP so they don’t get blamed for slowing AI efforts.

But putting oath tokens in config/mcp.json files is like leaving your keys in a fake rock labeled “keys” on your doorstep.

Local MCPs are a security nightmare.

There was a recent case where someone had a malicious vs code extension drain his crypto. That’s the same attack vector, but oauth tokens are at stake.