
Avi
@avi_lum
Followers
254
Following
3K
Media
147
Statuses
705
Security Research, AI Engineering, everything in between @OligoSecurity
Joined January 2022
@AnthropicAI has fixed the issue promptly and professionally - It's amazing to see OS projects that really care for their users' security!.
0
0
1
The inspector starts a local MCP proxy server that: - Accepts arbitrary bash commands as arguments - Has no auth - Binds to localhost, which is reachable by any webpage via #0000 tricks So yes, you read that right: visit a malicious website → get instant Remote Code Execution.
1
1
2
The MCP Inspector tool automatically runs every time you evaluate/debug an MCP project - it’s the standard method recommended by Anthropic, used by: - mcp dev - npx @modelcontextprotocol/inspector- Even OSS MCP servers from Google, OpenAI, Microsoft, etc.
1
1
3
RT @Uri__S: @lukOlejnik Usage of localhost APIs reminds me of @avi_lum's research . Interesting to see it's actual….
0
1
0
RT @mqst_: 🔓 0.0.0.0 Day: Exploiting Localhost APIs From the Browser. Blog: author: @avi_lum . #infosec
https://t.….
0
44
0
RT @shaunmmaguire: As a reminder, the Governor of Pennsylvania’s home was fire bombed. During the Jewish holiday of Passover. By a pro-Pale….
0
375
0
RT @GalElbaz1: You know our research made an impact when @e_kaspersky (!!!) shares it. Our #Airborne deep dive into a zero-click, wormab….
0
1
0
RT @e_kaspersky: AirBorne: Attacks on Apple devices through vulnerabilities in AirPlay. Why a big deal and how to stay safe from these att….
0
8
0
RT @OligoSecurity: Oligo Security researchers uncovered critical vulnerabilities in Apple's AirPlay protocol, affecting billions of devices….
0
16
0
RT @The_Cyber_News: 🚨 AirPlay 0-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi . Read more: ✅ A….
0
15
0
RT @a_greenberg: Flaws in Apple's AirPlay protocol for streaming media to speakers, TVs, and set-top boxes have left millions of these devi….
0
41
0
Can’t wait to see what we find next! .Check out the full research here: . And the @WIRED story about the disclosure here: . @GalElbaz1 @OligoSecurity.
0
2
3