Everyone is a builder now. Security needs visibility and control - without slowing innovation.

The AI ecosystem is the wild west 🐎 You connect a new MCP, skill, or agent... and find out it's sketchy after the damage is done. We built Market Space - discover & install AI tools that are secure by default 🪐 plutonium.pluto.security
1
4
46
2,867
The security assumption every AI team gets wrong: "As long as trust_remote_code=False is set, we are safe." ❌ We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control. A thread on how a routine model load turns into complete environment compromise 👇 1/3 🔍 The Exploit & ScaleBy abusing model configuration fields, an attacker can embed a malicious payload inside a configuration file. It executes arbitrary code even with remote code disabled. The affected versions were downloaded over 232M times while live. 2/3 🚨 The RiskSuccessful exploitation means full environment compromise—exposing cloud credentials, API keys, source code, and proprietary datasets. Impacts Transformers versions 4.56.0 through 5.2.x. 3/3 🛡️ Remediation• Upgrade to version 5.3.0 immediately. • Audit previously downloaded model configurations. • Move beyond checkbox security—static ecosystem flags aren't enough. Kudos to the Hugging Face team for the quick patch collaboration. 👇 Full technical breakdown link in the replies!
2
1
46
1,934
Last time, we published ClaudeSec - our security-first hub for the Claude ecosystem. Now, CopilotSec is officially LIVE. A new community knowledge hub for security of the Microsoft AI ecosystem, powered by Pluto. Ever wanted a single place to understand what Microsoft AI connectors actually do? Wondered which ones are high-risk? Trying to figure out how to securely deploy Copilot Studio, agents, MCP servers, or AI workflows in production? That’s exactly why we built CopilotSec. Inside you’ll find: 1,718 Microsoft ecosystem connectors mapped by capability and riskSecurity guides for Copilot Studio and Microsoft AI deploymentsCurated security updates and findings that actually matter to security teams Built for practitioners. Open to everyone. Give it a try and let us know what you think! Link in the first comment 👇
2
23
1,141
ClaudeSec is officially LIVE! Meet the new security-first hub for the Claude ecosystem, powered by @pluto_security. ❓Always yearned for a unified search of all existing extensions? ❓Ever wondered what ones are flagged as high-risk? ❓Dreaming of knowing how to deploy safely with Claude? All of this (and more) is now waiting for you on our new planet. Give it a go and let us know in the comments what you thought! Link in the first comment.
5
4
33
1,611
Our research team disclosed CVE-2026-33032, a critical CVSS 9.8 vulnerability in nginx-ui that exposed over 500K users to full server takeover through a single unauthenticated request. No credentials. No exploit chain. Actively exploited in the wild. The root cause: MCP endpoints that inherit an application's full capabilities but skip its security controls entirely. The pattern is clear - and it's only getting more common as agentic workflows connect deeper into enterprise workspace infrastructure. Most security teams have no visibility into what MCP servers are running in their environment, no inventory of the endpoints they're exposing, and no way to enforce it. Full breakdown → lnkd.in/dmbkkQAp As covered by The Hacker News → lnkd.in/gWTZt4e4
2
3
24
1,458
Our attendee list for the upcoming @pluto_security webinar now includes leaders from some of the world's most innovative tech firms. They’re all asking the same thing: How do we stop blocking tools like @cursor_ai , @n8n_io , and @Lovable and start securing them? We’re diving into the new risks introduced by AI builders and sharing a practical, enforceable framework for AI workspace security. See the strategies being used by the best in the business to move from "no" to "yes." Registration link: lnkd.in/dgqj6gfA
2
19
1,179