Azure MCP exploited: Maliciously leaking user's KeyVault secrets to attackers
tramlines.io
tramlines.io
“Don’t trust user input” “Validate user input” “Sanitize user input” mantras ring in my head.
Why weren’t they ringing in those developers heads? Or were they vibe coding??
Tongue firmly in cheek - or may be not.
The only reasonable way to prevent this is to firewall your services.