كيف أدى خادم MCP غير مصادق عليه إلى ثغرات تزوير الطلبات من جانب الخادم (SSRF)، وإدراج الملفات المحلية (LFI)، وسرقة بيانات اعتماد AWS
A real-world AIVigil finding from a customer environment. One unprotected AI integration endpoint with no login required. An attacker chained Server-Side Request Forgery, Local File Inclusion, and live AWS credential exfiltration into a potential full infrastructure takeover. This is how it happened, and how AIVigil found it first.
Written by
افتتاحية كلاودسك