Latio
Latio’s 2026 AI Security Market Report
An independent look at how the AI security market is evolving, what buyers are prioritizing, and why Latio recognized Pluto as an Endpoint AI Security Leader.
Reports, research, guides and free tools for securing the AI workspace.
Latio
An independent look at how the AI security market is evolving, what buyers are prioritizing, and why Latio recognized Pluto as an Endpoint AI Security Leader.
Pluto Research · Operation:MCP
Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing root access, production credentials, financial data and municipal citizen workflows.
Pluto Research · free hub
A free, vendor-neutral security catalog for the connectors, skills, plugins and MCP servers extending Claude, Copilot and beyond. See what’s safe before your team installs it.
Everything in the library, grouped by type.
Latio
An independent look at how the AI security market is evolving, what buyers are prioritizing, and why Latio recognized Pluto as an Endpoint AI Security Leader.
Gartner
“Shadow AI Demands Stricter Endpoint Application Control” and “Use the SAFE Framework to Secure AI Agents and Browsers in Endpoints”: what both notes say, and where Gartner named Pluto Security in each.
Pluto Research · Operation:MCP
Pluto Research found 179 exposed MCP server deployments across the internet. 147 accepted unauthenticated requests, exposing root access, production credentials, financial data and municipal citizen workflows.
ClaudeSec
The hardening checklist for Anthropic’s Slack-native agent, in priority order: who can invoke it, what each channel and repo can reach, where its data can go, and what to watch.
CopilotSec
Copilot Studio agents are in production in a lot of organizations, and the security work hasn’t kept up. A practical hardening guide for the platform.
ClaudeSec
Skills, Connectors (MCP) and Plugins look like distinct units but act as one bundle under a single click of consent. A practitioner’s map of where the code runs and where the risk sits.
ClaudeSec
Claude Cowork reads files, writes code, browses the web and executes tasks on your machine. What that new threat surface means for security teams, and how to govern it.
Pluto Research · free tool
A free tool from Pluto Research that scans public npm MCP servers for unauthenticated access, DNS rebinding, prompt injection and other risks before you install them.
Pluto Research
The full sourced timeline of the TeamPCP campaign, from the first Trivy compromise onward, with technical details, indicators and a free defender toolkit.
Pluto Research · free hub
A free, vendor-neutral security catalog for the connectors, skills, plugins and MCP servers extending Claude, Copilot and beyond. See what’s safe before your team installs it.
Pluto Research · free hub
A community knowledge hub for security across the Microsoft AI ecosystem: Copilot Studio, M365 Copilot and Azure AI Foundry. CopilotSec now lives inside Plutonium.
Pluto Research · free hub
Know what every Claude connector, extension and offering can actually do before you adopt it. ClaudeSec now lives inside Plutonium.
Pluto Security
The modern CISO’s dilemma: how to enable AI-driven productivity with tools like Cursor, n8n and Lovable without losing control, and what a practical, enforceable framework for AI workspace security looks like.