New quiz In-house vs on-demand: 10 questions to save you $500k+ in hiring mistakes and lost time10 questions to save you $500k+ Take the quiz

Podcast Episode 100

Episode 100 41 min

Why Your Employees' Favorite AI Tool Might Be Leaking Your Data

with Xia Hua · Traceforce

0:00 / 41:00

Also on Spotify, Apple Podcasts, Podbean, Player FM

Episode notes

Every employee at your company probably has ChatGPT, Claude, and Gemini installed, and nobody's tracking what data goes where. Xia Hua, co-founder and CEO of Traceforce, came back a year after her first appearance to show us what that looks like from the inside. Her team's open source scanner, MCP X-Ray, found a prompt injection flaw in Playwright, one of the most widely used MCPs, and she triggered it live with a single sentence. We also get into Anthropic's report on the espionage campaign that used Claude and a set of MCPs against about 30 organizations. And the bigger problem underneath it all, that data and instructions are now co-mingled, so any tool that reads text can be told what to do by that text.

Hosted by Jon McLachlan and Sasha Sinkevich — co-founders of YSecurity.

New episodes every other Tuesday

Got a story like this one?

We're always looking for practitioners who've been in the room when it mattered.