Episode Details
Back to Episodes
100. Why Your Employees' Favorite AI Tool Might Be Leaking Your Data
Description
Every employee at your company probably has ChatGPT, Claude, and Gemini installed, and nobody's tracking what data goes where. Xia Hua, co-founder and CEO of Traceforce, came back a year after her first appearance to show us what that looks like from the inside. Her team's open source scanner, MCP X-Ray, found a prompt injection flaw in Playwright, one of the most widely used MCPs, and she triggered it live with a single sentence. We also get into Anthropic's report on the espionage campaign that used Claude and a set of MCPs against about 30 organizations. And the bigger problem underneath it all, that data and instructions are now co-mingled, so any tool that reads text can be told what to do by that text.
Xia: www.linkedin.com/in/xia-hua-ph-d
TraceForce: www.traceforce.ai
MCP X-Ray: www.github.com/traceforce/mcp-xray
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io
π Sponsored by YSecurity
Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.
YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.
Book a free strategy call and we'll tell you exactly where you stand.
π Book your free call: 30 Min Meeting | YSecurity.io | Cal.com
π Learn more: YSecurity | On-Demand Cybersecurity Team for Startups β SOC 2 in 5 Months