100. Why Your Employees' Favorite AI Tool Might Be Leaking Your Data
JUL 29, 202641 MIN
/https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog11845528/100_-_Xia_Hua6upuv.png)
Description
Every employee at your company probably has ChatGPT, Claude, and Gemini installed, and nobody's tracking what data goes where. Xia Hua, co-founder and CEO of Traceforce, came back a year after her first appearance to show us what that looks like from the inside. Her team's open source scanner, MCP X-Ray, found a prompt injection flaw in Playwright, one of the most widely used MCPs, and she triggered it live with a single sentence. We also get into Anthropic's report on the espionage campaign that used Claude and a set of MCPs against about 30 organizations. And the bigger problem underneath it all, that data and instructions are now co-mingled, so any tool that reads text can be told what to do by that text.
Xia: www.linkedin.com/in/xia-hua-ph-d
TraceForce: www.traceforce.ai
MCP X-Ray: www.github.com/traceforce/mcp-xray
Jon: www.linkedin.com/in/jon-mclachlan
Sasha: www.linkedin.com/in/aliaksandr-sinkevich
YSecurity: www.ysecurity.io
🔒 Sponsored by YSecurity
Closing a big deal and getting hit with a vendor questionnaire, SOC 2 request, or pen test requirement? That's exactly what we handle.
YSecurity embeds a team of security engineers with backgrounds from Apple, Uber, Microsoft, Robinhood, and Brex directly into your company. No full-time hire, no bloated retainer. You set a monthly cap and we handle everything.
Book a free strategy call and we'll tell you exactly where you stand.
👉 Book your free call: 30 Min Meeting | YSecurity.io | Cal.com
👉 Learn more: YSecurity | On-Demand Cybersecurity Team for Startups — SOC 2 in 5 Months


/https://pbcdn1.podbean.com/imglogo/image-logo/11845528/YSecurity-Podcast-Cover-Centere.jpg)