Insights
Security for MCP, AI agents and compliance
Practical guides instead of buzzwords. Every post comes from CyberSec42 Research and follows the same principle as our reviews: name the one property your product depends on, and back it with evidence rather than adjectives.
MCP and agent security
How MCP servers and AI agents become attack surface, and how to secure them structurally.
MCP and agent security
Securing MCP servers: the practical guide
An MCP server is not a plugin, it runs with full access. The most common vulnerability classes and the concrete countermeasures at a glance.
Read the post
MCP and agent security
The OWASP MCP Top 10, explained in practice
The open reference for MCP security, class by class: where each one breaks and how to counter it concretely.
Read the post
MCP and agent security
The OWASP Top 10 for Agentic Applications, explained in practice
The new OWASP reference for autonomous AI agents (ASI01 to ASI10), class by class: from goal hijack to rogue agents.
Read the post
MCP and agent security
MCP and OAuth: securing the trust anchor
MCP uses OAuth 2.1 as its trust anchor. How to pin the authorization server and PRM origin, cut the scope, and verify the token audience.
Read the post
MCP and agent security
Prompt injection and tool poisoning in MCP servers
The most dangerous MCP class: injected content triggers the server's writing tools. How to prevent it structurally.
Read the post
MCP and agent security
AI agent security: the overview
AI agents act with real permissions in real systems. The broad entry point to their attack surfaces, from tool access to MCP.
Read the postPenetration testing and security testing
What a defensible security proof costs, how it runs, and when which test fits.
Penetration testing
Penetration testing: process, duration and what it costs
How a penetration test runs, how long it takes, and what drives the cost. An honest overview of scope and proof.
Read the post
Fundamentals
Vulnerability assessment: what it is and when you need one
What a vulnerability assessment delivers, how it differs from a penetration test, and when each one is the right call.
Read the postCompliance and regulation
NIS2, ISO 27001 and the path to an audit-ready proof, without certification theater.
NIS2
NIS2: who is affected and what to do now
NIS2 covers far more organizations than the old directive. Who is affected, which deadlines apply, and the concrete steps due now.
Read the post
ISO 27001 for software teams
ISO 27001 for SaaS and startups: what really counts
How a lean ISMS takes shape and how to collect evidence that holds up in enterprise procurement. ISO 27001 placed against SOC 2.
Read the postIs your product defensibly secure?
In a free initial call we name the one property your product depends on, and whether it is provable. Every finding comes with a proof of concept, not a guess.
Book a free call