Invariant Labs (@invariantlabsai) 's Twitter Profile
Invariant Labs

@invariantlabsai

Invariant Labs makes AI Agents secure and reliable.

ID: 1810294347474345984

linkhttp://invariantlabs.ai calendar_today08-07-2024 12:47:04

106 Tweet

533 Followers

27 Following

Luca Beurer-Kellner (@lbeurerkellner) 's Twitter Profile Photo

πŸ”΄πŸŒŽ New MCP attack on BrowserMCP We show an MCP attack on the popular BrowserMCP. It allows attackers to read arbitrary files from your machine, when the agent visits the website below. Try yourself with: access.invariantlabs.ai No bad MCP server needed. (1/n)πŸ‘‡

πŸ”΄πŸŒŽ New MCP attack on BrowserMCP

We show an MCP attack on the popular BrowserMCP.
It allows attackers to read arbitrary files from your machine, when the agent visits the website below.

Try yourself with: access.invariantlabs.ai

No bad MCP server needed.

(1/n)πŸ‘‡
Marc Fischer (@marc_r_fischer) 's Twitter Profile Photo

We recently shipped a lot of updates to mcp-scan: - whitelisting of tools - Improvements to the server (reducing false-positives, improving detection) - run via npm/npx Much more coming soon! github.com/invariantlabs-… #mcp

Bill Doerrfeld (@doerrfeldbill) 's Twitter Profile Photo

MCP is the hottest thing in AI right now, but people aren't really talking about the security implications... I covered a recently discovered exploit and mitigations on the The New Stack today: thenewstack.io/building-with-…

Invariant Labs (@invariantlabsai) 's Twitter Profile Photo

We are proud to share that AgentDojo, an Invariant research project done with ETH ZΓΌrich, has won the first price of the Center for AI Safety SafeBench competition. We truly appreciate this recognition from the community. Learn More: invariantlabs.ai/blog/agentdojo…

Invariant Labs (@invariantlabsai) 's Twitter Profile Photo

πŸ”΅ New release: Invariant MCP-scan v0.2 is here! Track, audit & secure all local MCP traffic with static+dynamic scanning, local guardrails, and customizable policies. Ideal for orgs prioritizing agent security & compliance. Docs: explorer.invariantlabs.ai/docs/mcp-scan/ #AI #DevSecOps

πŸ”΅ New release: Invariant MCP-scan v0.2 is here!

Track, audit & secure all local MCP traffic with static+dynamic scanning, local guardrails, and customizable policies. 

Ideal for orgs prioritizing agent security & compliance.

Docs: explorer.invariantlabs.ai/docs/mcp-scan/

#AI #DevSecOps
Luca Beurer-Kellner (@lbeurerkellner) 's Twitter Profile Photo

😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked. We discovered a new attack on agents using GitHub’s official MCP server, which can be exploited by attackers to access your private repositories. creds to Marco Milanta (1/n) πŸ‘‡

😈 BEWARE: Claude 4 + GitHub MCP will leak your private GitHub repositories, no questions asked.

We discovered a new attack on agents using GitHub’s official MCP server,  which can be exploited by attackers to access your private repositories.

creds to <a href="/marco_milanta/">Marco Milanta</a>

(1/n) πŸ‘‡
Invariant Labs (@invariantlabsai) 's Twitter Profile Photo

Invariant researchers have uncovered a new security flaw in GitHub’s official MCP server, enabling attackers to exfiltrate private repository data. The toxic flow was identified during an automated scan using Invariant's security stack. Learn more: invariantlabs.ai/blog/mcp-githu…