Secure GenAI
Secure GenAI Podcast
Common security risks in MCP, governing AI agents, GenAI Security risks and best practices, AI safety lecture, pixnapping, AWS outage.
0:00
-15:31

Common security risks in MCP, governing AI agents, GenAI Security risks and best practices, AI safety lecture, pixnapping, AWS outage.

GenAI Safety & Security | Oct 20 - Oct 26, 2025

If you enjoy our newsletter, please consider to be a paid subscriber to help us keep more news and updates coming out.

Secure GenAI is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Highlights

  • Common security risks in MCPs.

  • Governing AI agents.

  • GenAI Security: Risk & Best Practices.

  • AI safety lecture 7: Guest lecture by Joel Becker.

  • New “Pixnapping” attack discovered.

  • AWS Outage.


Deep Dive

Common security risks in MCPs. SPLX

  • Prompt injection

  • Authentication and authorization failures

  • Tool poisoning

  • Command injection

  • Rug pulls

DataBricks: Governing AI agents DeepLearning.ai

  • 1 hour 30 minutes, 9 video lectures.

  • Lifecycle management, risk management, security and observability.

  • Design with safety, compliance and production-ready agents.

  • Build, evaluate and prepare your agent using MLflow.

  • Deploy a governed agent with a secure, traceable endpoint in Databricks.

GenAI Security: Risk & Best Practices Wiz

  • Full-stack AI security discipline

  • Protects models, data, infrastructure, interfaces

  • Risks: poisoning, data leaks, deepfakes

  • Compliance: EU AI Act challenges

  • Guided by OWASP, NIST RMF

  • Enforce zero-trust access controls

  • Develop AI-specific incident response

AI Safety Lecture 7: Guest Lecture by Joel Becker Boaz Barak Metr

  • Metr GPT-5 Evaluation Results.

  • Surveys unreliable.

  • Benchmarks don’t tell a full story.

  • Early 2025 AI slows down.

  • 2026 and beyond AI: More performant.

New “Pixnapping” attack discovered MalwareBytesLabs

  • Steals data via pixel data

  • Bypasses browser & app security

  • Targets 2FA codes, more

  • Google partially patched vulnerability

  • Consider hardware 2FA tokens

AWS Outage Guardian

  • A bug in DynamoDB’s automated DNS.

  • Caused by an empty DNS record in the US-East-1.

  • Led to outages of numerous other AWS tools.

  • 2000 companies affected with 8.1 million user reports.

  • Future Outages: Consider Bluetooth to control functions.

Notice: Introduce my new book Nothing matters - The Microsoft CrowdStrike event caused by an empty file that disrupts several services and products including television, airports, supermarkets and more.

Thanks for reading Secure GenAI ! This post is public so feel free to share it.

Share

Discussion about this episode

User's avatar