The Security Podcast of Silicon Valley

← The Security Podcast of Silicon Valley29 jul · 41 min

100. Why Your Employees' Favorite AI Tool Might Be Leaking Your Data

100. Why Your Employees' Favorite AI Tool Might Be Leaking Your Data29 jul41 min

Every employee at your company probably has ChatGPT, Claude, and Gemini installed, and nobody's tracking what data goes where. Xia Hua, co-founder and CEO of Traceforce, came back a year after her first appearance to show us what that looks like from the inside. Her team's open source scanner, MCP X-Ray, found a prompt injection flaw in Playwright, one of the most widely used MCPs, and she triggered it live with a single sentence. We also get into Anthropic's report on the espionage campaign that used Claude and a set of MCPs against about 30 organizations. And the bigger problem underneath it all, that data and instructions are now co-mingled, so any tool that reads text can be told what to do by that text.

Xia: www.linkedin.com/in/xia-hua-ph-dTraceForce: www.traceforce.aiMCP X-Ray: www.github.com/traceforce/mcp-xray Jon: www.linkedin.com/in/jon-mclachlanSasha: www.linkedin.com/in/aliaksandr-sinkevichYSecurity: www.ysecurity.io

🔒 Sponsored by YSecurity

Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.

YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.

Book a free strategy call and we'll tell you exactly where you stand.

👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com

👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months