• Cloudflare today launched MCP Server Portals in open beta, a groundbreaking capability designed to centralize, secure, and observe all Model Context Protocol (MCP) connections in an organization. 

    By routing every MCP request through a single portal endpoint, Cloudflare One customers can now enforce Zero Trust policies, gain comprehensive visibility, and dramatically reduce the attack surface exposed by AI-driven integrations.

    Key Takeaways
    1. Centralized MCP connections via a single portal with Zero Trust policies.
    2. Enforced SASE controls and unified logging for real-time security and visibility.
    3. Curated least-privilege access to eliminate unmanaged AI endpoints.

    Model Context Protocol

    The Model Context Protocol (MCP) is rapidly becoming the universal standard for connecting large language models (LLMs) such as ChatGPT, Claude, and Gemini to enterprise applications. MCP defines two core components:

    MCP Client: The LLM front-end requesting context or invoking actions.

    MCP Server: The application endpoint exposing Resources, Prompts, and Tools to the client.

     Architecture Overview
     Architecture Overview

    A minimal MCP Server configuration in YAML illustrates the simplicity of integration:

    Cloudflare Unveils MCP Server Portals

    This open-source protocol transforms isolated LLMs into collaborative teammates by allowing structured API calls, dynamic prompts, and secure context retrieval.

    Enhancing Security 

    While MCP unlocks integration, it also creates a sprawling new attack surface prone to prompt injection, supply chain exploits (e.g., CVE-2025-6514 in npm authentication libraries), and “confused deputy” privilege escalations. 

    MCP Server Portals address these risks by acting as a single front door:

    Integrate directly with Cloudflare One’s Secure Access Service Edge (SASE) to apply multi-factor authentication, device posture checks, and geofencing on MCP traffic mirroring controls used for human users.

    MCP servers
    MCP servers

    Aggregate every MCP request, prompt invocation, and tool execution into a unified audit log. Security teams can now detect anomalous behaviors such as unusual data-exfiltration patterns or unauthorized tool usage in real time.

    Administrators register MCP servers with the portal, approve them, and assign permissions. Users only see the resources and tools explicitly authorized for their role, eliminating shadow AI endpoints.

    Rather than distributing multiple endpoint URLs, users configure a single Portal URL in their MCP client. New servers become instantly available through the portal without manual updates, according to Cloudflare’s advisory.

    MCP Server Portals integrate with Cloudflare Access for seamless OAuth-based authorization, whether applications are hosted on Cloudflare or external domains. 

    Future enhancements will include AI-powered WAF rules to block prompt-injection attacks, managed MCP server hosting via Cloudflare’s AI Gateway, and built-in machine learning models for anomaly detection.

    Get started today by visiting the Access > AI Controls page in your Zero Trust Dashboard. MCP Server Portals are now in open beta for all Cloudflare One customers, offering a secure path to empower AI innovation without compromising safety.

    Tired of Filling Forms for security & Compliance questionnaires? Automate them in minutes with 1up! Start Your Free Trial Now!

    The post Cloudflare Launches MCP Server Portals – A Unified Gateway to All MCP Servers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has imposed sanctions on Russian national Vitaliy Sergeyevich Andreyev, DPRK official Kim Ung Sun, Chinese entity Shenyang Geumpungri Network Technology Co., Ltd. DPRK-based Korea Sinjin Trading Corporation for their involvement in a sophisticated fraudulent scheme involving information technology workers orchestrated by the Democratic […]

    The post U.S. Treasury Sanctions North Korean IT Worker Network Funding Weapons Programs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Picture this: Your team rolls out some new code, thinking everything’s fine. But hidden in there is a tiny flaw that explodes into a huge problem once it hits the cloud. Next thing you know, hackers are in, and your company is dealing with a mess that costs millions. Scary, right? In 2025, the average data breach hits businesses with a whopping $4.44 million bill globally. And guess what? A big

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has issued a high-severity security advisory warning of a dangerous vulnerability in its Nexus 3000 and 9000 Series switches that could allow attackers to trigger denial of service (DoS) attacks through crafted network packets. The vulnerability, tracked as CVE-2025-20241 and assigned a CVSS score of 7.4, affects the Intermediate System-to-Intermediate System (IS-IS) feature in Cisco NX-OS […]

    The post Cisco Nexus 3000 & 9000 Vulnerability Enables DoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Every day, businesses, teams, and project managers trust platforms like Trello, Asana, etc., to collaborate and manage tasks. But what happens when that trust is broken? According to a recent report by Statista, the average cost of a data breach worldwide was about $4.88 million. Also, in 2024, the private data of over 15 million Trello user profiles was shared on a popular hacker forum. Yet,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Global cybersecurity leader CrowdStrike announced its intention to acquire Onum, a pioneer in real-time telemetry pipeline management, in a deal reportedly valued at $290 million.

    The acquisition, unveiled Wednesday, aims to significantly enhance CrowdStrike’s Falcon Next-Gen SIEM platform, transforming it into a more powerful data foundation for modern, AI-driven security operations.

    The integration of Onum’s technology is set to address a critical challenge in security operations: managing and processing vast amounts of data efficiently. Onum’s platform acts as both a high-speed data pipeline and an intelligent filter, streaming refined, high-quality data directly into the Falcon platform.

    “Our Next-Gen SIEM is the engine that powers the modern SOC, and data is the fuel that makes the engine run,” said George Kurtz, CEO and founder of CrowdStrike.

    “Onum is both a pipeline and a filter, which will stream high-quality, filtered data directly into the platform to drive autonomous cybersecurity at scale. This is how we stop breaches at the speed of AI while giving customers complete control over their entire data ecosystem.”

    Built on a proprietary in-memory architecture, Onum’s technology offers significant performance advantages. The company claims it can deliver up to five times more events per second than its nearest competitor.

    By enabling “in-pipeline analysis,” Onum allows for AI-powered detections to occur at the data source, even before the data enters the Falcon platform.

    This innovative approach promises up to 70 percent faster incident response times with 40 percent less ingestion overhead. Furthermore, its smart filtering capabilities can reduce data storage costs by as much as 50 percent.

    Historically, migrating data into a new SIEM has been a major bottleneck for security teams, often requiring complex third-party tools and significant effort.

    This acquisition is designed to eliminate that friction by making data streaming and in-pipeline detection a native function within the Falcon platform, accelerating SOC transformation for customers.

    “Onum was founded on the belief that pipelines should do more than transport data, they should transform data into real-time intelligence,” said Pedro Castillo, founder and CEO of Onum. “By joining CrowdStrike, we can deliver this vision at unprecedented scale to accelerate SOC transformation on a global scale.”

    The acquisition positions CrowdStrike to further solidify its Falcon platform as the central operating system for cybersecurity, expanding its capabilities beyond core security into broader IT observability. The transaction is subject to customary closing conditions.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

      The post CrowdStrike Set to Acquire Onum in $290 Million Deal to Enhance Falcon Next-Gen SIEM appeared first on Cyber Security News.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

    1. Experts have described methods for mimicking the strategies of the advanced persistent threat (APT) group Scattered Spider in a recent in-depth analysis by cybersecurity company Lares, allowing enterprises to strengthen their defenses through adversarial cooperation. Lares specializes in threat emulation, replicating real-world tactics, techniques, and procedures (TTPs) observed in cybercriminal activities. By dissecting incidents like […]

      The post New Research Explores Emulating Scattered Spider Tactics in Real-World Scenarios appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

    2. PromptLock, a novel ransomware strain discovered by the ESET Research team, marks the first known instance of malware harnessing a local large language model to generate its malicious payload on the victim’s machine. Rather than carrying pre-compiled attack logic, PromptLock ships with hard-coded prompts that instruct a locally hosted OpenAI gpt-oss:20b model—accessed via the Ollama […]

      The post First AI-Powered Ransomware “PromptLock” Uses OpenAI gpt-oss-20b for Encryption appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

    3. The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm package and other auxiliary plugins with data-gathering capabilities. “Malicious versions of the nx package, as well as some supporting plugin packages, were published to npm, containing code that scans the file system, collects credentials,

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

    4. Over 1,400 developers discovered today that a malicious post-install script in the popular NX build kit silently created a repository named s1ngularity-repository in their GitHub accounts. 

      This repository contains a base64-encoded dump of sensitive data wallet files, API keys, .npmrc credentials, environment variables, and more harvested directly from developers’ file systems.

      Key Takeaways
      1. Malware in the NX build tool steals credentials and creates GitHub repos.
      2. Targets Claude and Gemini CLIs for advanced data exfiltration.
      3. Delete suspicious repos, update NX, and rotate secrets urgently.

      AI-Assisted Data Exfiltration

      Semgrep reports that attackers leveraged the NX post-install hook via a file named telemetry.js to execute malicious code immediately after package installation. 

      The malware first collects environment variables and attempts to locate a GitHub authentication token via the GitHub CLI. Armed with credentials, it then creates a public repository such as s1ngularity-repository-0 and commits the stolen data in results.b64.

      What makes this campaign particularly novel is its integration with Claude Code CLI or Gemini CLI. If either AI-powered CLI is present, the malware issues a carefully crafted prompt to conduct fingerprintable filesystem scans:

      NX Build Tool Hacked

      This AI-driven approach offloads the bulk of signature-based filesystem enumeration to the LLM, complicating traditional malware detection.

      Affected NX Versions and Mitigations

      • @nx/devkit 21.5.0, 20.9.0
      • @nx/enterprise-cloud 3.2.0
      • @nx/eslint 21.5.0
      • @nx/key 3.2.0
      • @nx/node 21.5.0, 20.9.0
      • @nx/workspace 21.5.0, 20.9.0
      • @nx 20.9.0–20.12.0, 21.5.0–21.8.0

      Developers using any impacted versions should immediately run:

      or inspect lockfiles for vulnerable dependencies. 

      • Search for unauthorized repositories.
      • Delete any s1ngularity-repository* you find.
      • Update NX to safe version 21.4.1 (vulnerable versions removed from npm).
      • Rotate all exposed secrets: GitHub tokens, npm credentials, SSH keys, environment variables.
      • Remove malicious shutdown directives in shell startup files (e.g., .bashrc).

      As the incident unfolds, organizations are urged to monitor repository creations and enforce strict post-installation auditing.

      Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

      The post NX Build Tool Hacked with Malware That Checks for Claude or Gemini to Find Wallets and Secrets appeared first on Cyber Security News.

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶

      ¶¶¶¶¶