About the author

Yotam Perkal leads Security Research at Pluto Security, where he focuses on securing AI-native development environments and uncovering emerging risks in AI-driven software workflows. With over a decade of experience in cybersecurity, his work sits at the intersection of offensive research, vulnerability management, and software supply chain security.

Previously, Yotam led Threat Research at Zscaler, headed Vulnerability Research at Rezilion, and held multiple roles within the PayPal security organization.

He is an active contributor to cross-industry initiatives focused on AI security, vulnerability management, and software supply chain risk.

Related Posts

MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments

A working exploit for MCPfluence appeared on a cybercrime forum just 20 days after responsible disclosure. Pluto Research traces the attack path, examines similar exploitation…

Malicious Servers, Clean Scans: The Dangerous Illusion of a Clean MCP Scan

Pluto Research tested five public MCP security scanners against malicious servers. Several returned clean or zero-finding results, exposing the gap between what a scan checks…

Your CI Pipeline Is a Credential Vending Machine: 7 Lessons from the TeamPCP supply-chain attacks

TeamPCP turned trusted automation into a path for credential theft and lateral compromise. Based on 37 mapped incidents, here are seven controls defenders should prioritize…

The Manipulated Agent: When Apify’s MCP Turns Against You

Apify’s official MCP connector let a scraped web page trigger a second, authenticated Apify action nobody asked for. Chapter 3 of Operation: MCP breaks down…

The MCP Debrief – What’s Actually Running on Your Endpoints

MCP has quickly become the default way enterprise AI agents reach internal systems, and most security teams do not yet have a real inventory of…

Nebula Deck: A Malicious VS Code Extension Built to Survive a Windows Reinstall

A fake project planner on the VS Code Marketplace starts working the second your editor finishes loading. It downloads a Windows script, unpacks a payload…

PhantomBoard: A Fake Trello Extension for VS Code That Quietly Installs XWorm

Three VS Code extensions, three throwaway publisher accounts, three days, and one backend IP address that never changed once. Read the source of these three…

Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record

Two vulnerabilities in CircleCI’s official MCP server: a CVSS 10.0 that turns a filename into code execution inside your CI pipeline, and a CVSS 8.3…

Securing Claude Tag: A Practical Hardening Guide

Claude Tag’s security comes almost entirely from configuration – who can invoke it, what each channel and connected repo can reach, where its data can…