Research from the AI frontier
Disclosures, live malware campaigns and deep dives into how AI agents really work.
We take apart the AI tools people use at work
Pluto Research is the security research team at Pluto Security. We reverse-engineer agent platforms, audit MCP servers and IDE extensions, track live malware campaigns, and report what we find to the vendors before we publish the details.
Much of that work is also available as free community tools, listed further down this page.
- research stories
- 31
- coordinated disclosures
- 8
- ongoing series
- 4
Latest research
All research on the BlogInside Claude Code Function Hooks: The Trust Problem Behind Claude Mods
MCP Through an Attacker’s Eyes: The New Path Into Enterprise Environments
Follow a story from first finding to fix
7 stories · oldest first
Operation: MCP
Our research into the security boundaries created when organizations connect AI agents to tools, data and infrastructure — from adoption data to critical flaws in popular MCP servers.
11 stories · oldest first
ClaudeSec
Reverse-engineering and hardening guides for the Anthropic ecosystem: Cowork, Managed Agents, Claude Tag, Artifacts, Office add-ins and Claude Code.
3 stories · oldest first
CopilotSec
How the Microsoft AI ecosystem actually works, and how to secure it — starting with Copilot Studio.
5 stories · oldest first
Malicious Extensions
Live malware campaigns we tracked across the VS Code Marketplace and Open VSX — and the gaps that let them in.
Vulnerabilities we found and reported
Coordinated disclosures in popular MCP servers and AI tooling, with the full write-up for each.
-
Apify MCP server
The Manipulated Agent: When Apify’s MCP Turns Against You
CVE-2026-46341CVE-2026-81093
High CVSS 8.6 -
jupyter-mcp-server
The Notebook Backdoor: Taking Over jupyter-mcp-server’s Live Notebook Connection
CVE-2026-77318CVE-2026-77359
Critical CVSS 9.3 -
CircleCI MCP server
Vicious Circle: Owning CircleCI’s MCP Server With a Filename and a DNS Record
GHSA-m9x7-h9px-p447GHSA-jwj7-74jh-p5c4
Critical CVSS 10.0 -
mcp-memory-service
Total Recall: How Two CVEs Let Any Website Read, Rewrite, and Wipe Your AI’s Memory
CVE-2026-33010CVE-2026-29787
High CVSS 8.1 -
gitlab-mcp
One Request to Own Every Repo: How We Hijacked GitLab Through Its MCP Server
GHSA-cv3r-c5h8-f4g5GHSA-2h44-8472-frjj
Critical CVSS 9.8 -
HuggingFace transformers
Unauthenticated Remote Code Execution in HuggingFace Transformers via Config Injection
CVE-2026-4372
High CVSS 7.8 -
nginx-ui (MCP endpoint)
MCPwn: A CVSS 9.8 One-Line MCP Bug That Hands Over Your Nginx to Anyone on the Network – Actively Exploited in the Wild
CVE-2026-33032
Critical CVSS 9.8 -
mcp-atlassian
MCPwnfluence: Critical Unauthenticated SSRF to RCE Attack Chain in the Most Widely Used Atlassian MCP Server
CVE-2026-27825CVE-2026-27826
Critical CVSS 9.1
Free tools from Pluto Research
What we learn in the lab, packaged so anyone can use it.
-
MCP Inspector
Checks an MCP server for security risks before you install it. Built from the findings behind Operation: MCP.
-
Plutonium
A free, vendor-neutral security hub for the AI assistant ecosystem: risk catalogs, hands-on guides and curated news.
-
ClaudeSec
A community knowledge hub for Claude ecosystem security — the Anthropic surface within Plutonium.
-
CopilotSec
A community knowledge hub for securing the Microsoft AI ecosystem — the Microsoft surface within Plutonium.
Reports, stories and the basics
- Research reports Resources Research reports and analyst coverage in the Resources hub, ready to download and share. Browse research reports
- Editorial The Blog Pluto’s perspectives, research stories and company news. Read the Blog
- Explainers & reference Learn Plain-language explainers on AI security, plus the glossary and FAQs. Start learning