Insights

Security for MCP, AI agents and compliance

Practical guides instead of buzzwords. Every post comes from CyberSec42 Research and follows the same principle as our reviews: name the one property your product depends on, and back it with evidence rather than adjectives.

MCP and agent security

How MCP servers and AI agents become attack surface, and how to secure them structurally.

MCP and agent security

Securing MCP servers: the practical guide

An MCP server is not a plugin, it runs with full access. The most common vulnerability classes and the concrete countermeasures at a glance.

Read the post
MCP and agent security

The OWASP MCP Top 10, explained in practice

The open reference for MCP security, class by class: where each one breaks and how to counter it concretely.

Read the post
MCP and agent security

The OWASP Top 10 for Agentic Applications, explained in practice

The new OWASP reference for autonomous AI agents (ASI01 to ASI10), class by class: from goal hijack to rogue agents.

Read the post
MCP and agent security

MCP and OAuth: securing the trust anchor

MCP uses OAuth 2.1 as its trust anchor. How to pin the authorization server and PRM origin, cut the scope, and verify the token audience.

Read the post
MCP and agent security

Prompt injection and tool poisoning in MCP servers

The most dangerous MCP class: injected content triggers the server's writing tools. How to prevent it structurally.

Read the post
MCP and agent security

AI agent security: the overview

AI agents act with real permissions in real systems. The broad entry point to their attack surfaces, from tool access to MCP.

Read the post

Penetration testing and security testing

What a defensible security proof costs, how it runs, and when which test fits.

Penetration testing

Penetration testing: process, duration and what it costs

How a penetration test runs, how long it takes, and what drives the cost. An honest overview of scope and proof.

Read the post
Fundamentals

Vulnerability assessment: what it is and when you need one

What a vulnerability assessment delivers, how it differs from a penetration test, and when each one is the right call.

Read the post

Compliance and regulation

NIS2, ISO 27001 and the path to an audit-ready proof, without certification theater.

NIS2

NIS2: who is affected and what to do now

NIS2 covers far more organizations than the old directive. Who is affected, which deadlines apply, and the concrete steps due now.

Read the post
ISO 27001 for software teams

ISO 27001 for SaaS and startups: what really counts

How a lean ISMS takes shape and how to collect evidence that holds up in enterprise procurement. ISO 27001 placed against SOC 2.

Read the post

Is your product defensibly secure?

In a free initial call we name the one property your product depends on, and whether it is provable. Every finding comes with a proof of concept, not a guess.

Book a free call