coderinsan

↗ HN profile [ 224 ms ] full profile
Karma
0
Created
()
Submissions
0
  1. Looks like OpenAI's rogue agents used https://ntfy.sh as a pub/sub channel. This payload publishes via GET in an img tag, pulls chunked base64 JS from a topic, and eval()'s it. Remote code via GET only. Proof:…

  2. Hey HN, we’re officially launching Tramlines.io! The idea: We now have a ton of official MCP servers for tools like Notion, Linear, Sentry, etc.—but it’s still a nightmare to use these securely. They’re susceptible to…

  3. Provide the GitHub README of any MCP server as input, and the tool generates end-to-end visualizations of potential exploits in that server.

  4. Realized many people struggle to visualize how data flow, control flow, or side channel attacks can exploit your MCP setup. I hacked together a quick interface to help people see these exploits more clearly.