Ultra is aligned with and an early contributor to AARM and the Agentic Trust Control Framework.

RESOURCES

Everything we know
about securing agents.

Product announcements, customer stories, and in-depth research on the MCP threat landscape. Written by the team building the security layer for it.

2025-010

Cross-Session Context Leakage

Sensitive data leaking between sessions, agents, and users through accumulated context windows, persistent memory, and shared server state.

Read →
2025-009

MCP Credential & Secrets Exposure

How plaintext credentials in MCP config files, environment variables, and error messages create a massive, largely unmonitored attack surface.

Read →
2025-008

MCP Observability & Audit Logging

Building comprehensive audit trails and real-time monitoring for all agent-to-tool interactions.

Read →
2025-007

Rug Pull Attacks in MCP

Trusted MCP servers that change behavior post-deployment to exfiltrate data or manipulate agent actions.

Read →
2025-006

Jailbroken AI

Techniques that bypass model safety layers through crafted MCP contexts, enabling restricted actions.

Read →
2025-005

Shadow AI

Unauthorized AI agents and MCP connections that operate outside IT visibility, bypassing security controls.

Read →
2025-004

MCP Security Guardrails

Designing and deploying policy-driven constraints that keep AI agents operating within safe boundaries.

Read →
2025-003

Tool Poisoning Attacks

Malicious MCP servers that masquerade as legitimate tools to intercept sensitive data and corrupt agent behavior.

Read →
2025-002

Command Injection in MCP Tools

Exploiting unsanitized inputs in MCP tool calls to execute arbitrary commands on connected systems.

Read →
2025-001

MCP Endpoint & Inventory Sprawl

How unchecked growth of MCP servers creates hidden attack surfaces and operational blind spots across your AI infrastructure.

Read →

Browse the full research library →