frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

The Permission Pitfall: Securing MCP Servers Without Limiting Value

https://www.joinformal.com/blog/the-permission-pitfall-securing-mcp-servers-without-limiting-value/
2•pyoo•1d ago

Comments

pyoo•1d ago
Last week Invariant Labs discovered a vulnerability in the Github MCP that lets you exfiltrate data from private repos via a public issue through prompt injection.

At the root of the issue was the lack of implemented granular permissions. Claude Desktop authenticates to Github via a personal access token (PAT) and over permissive PATs are what allowed the prompt injection.

When digging deeper, the challenge you face is that the permissions allowed by the base system (e.g., Github) does not allow you to implement least privilege. An agent that creates and commits PRs must also be given the ability to approve and merge them. This makes you choose between enforcing least privilege and increasing the value an agent can provide.

You may have guessed it, but I believe the solution is to have a decoupled centralized permissions layer on top of what the system natively gives. This way you can ensure an agent can create PRs without ever approving or merging them.

The goal is to not limit the ability of the agent but to provide the right guardrails in which it can operate. You can read the blog to see how we we're able to achieve this!

Show HN: Find your next cybersecurity job

https://www.cyber-security.careers
1•delta234•1m ago•0 comments

The golden era of flying is now

https://www.theupwing.com/thegoldeneraofflyingisnow/
1•dionysou•2m ago•0 comments

Ask HN: What are your fav/goto decision making hacks/heuristics?

1•ottaborra•4m ago•0 comments

Crayfish Plague

https://en.wikipedia.org/wiki/Crayfish_plague
1•tarcar•4m ago•0 comments

Silicon Valley wants to help me make a superbaby. Should I let it?

https://sfstandard.com/2025/06/01/silicon-valley-wants-to-help-me-make-a-superbaby-should-i-let-it/
1•MukundMohanK•7m ago•0 comments

Freedesktop team member closes all open xserver merge requests

https://gitlab.freedesktop.org/xorg/xserver/activity
1•theshrike79•10m ago•1 comments

I accidentally hacked a hotel switchboard

https://myit.substack.com/p/accidentally-hacked-a-hotel-switchboard
1•TowerTall•13m ago•0 comments

How to get smart again: the anti brain rot formula

https://postcardsbyelle.substack.com/p/how-to-get-smart-again
2•babushkaboi•16m ago•1 comments

Show HN: Is Your Company's AI Just Indians?

https://indian-company-checker.vercel.app/
1•thedeep_mind•20m ago•1 comments

Show HN: A React layout component for proper staggered grid/Masonry layout

https://github.com/biniamkiros/sentereige
1•biniamkiros•21m ago•0 comments

The Human and Ecological Costs of Perfume

https://worldsensorium.com/the-human-and-ecological-costs-of-perfume/
1•dnetesn•21m ago•0 comments

The Ocean Odyssey of Wilson

https://nautil.us/the-ocean-odyssey-of-wilson-1215754/
1•dnetesn•22m ago•0 comments

The bizarre story of a maths proof that is only true in Japan

https://www.newscientist.com/article/2482461-the-bizarre-story-of-a-maths-proof-that-is-only-true-in-japan/
8•monksdream•26m ago•1 comments

The Global Rise of AI Tools: What It Means for Work and Creativity in 2025

1•deepmistry•38m ago•0 comments

Aether: A CMS That Gets Out of Your Way

https://lebcit.github.io/post/meet-aether-a-cms-that-actually-gets-out-of-your-way/
3•LebCit•40m ago•0 comments

Proxy Services Feast on Ukraine's IP Address Exodus

https://krebsonsecurity.com/2025/06/proxy-services-feast-on-ukraines-ip-address-exodus/
3•Daviey•48m ago•0 comments

Benchmarking Is Hard Sometimes (postgresql)

https://vondra.me/posts/benchmarking-is-hard-sometimes/
2•biehl•50m ago•0 comments

Passkey Deployment Checklist

https://web.dev/articles/passkey-checklist
1•vdelitz•51m ago•0 comments

Save Millions on Your Cloud Bill: 11 Strategies for Kubernetes Cost Optimization

https://blog.cleancompute.net/p/kubernetes-cost-optimization
3•nibir•53m ago•0 comments

Show HN: TypeBridge – Zero Ceremony Compile-time RPC for client/server

https://github.com/uptownhr/TypeBridge
2•uptownhr•56m ago•1 comments

Tackling performance issues caused by load from bots

https://progress.opensuse.org/news/125
3•fionera•57m ago•0 comments

Show HN: Bulktopus – Generate All Your Ad and Social Media Images 10x Faster

https://www.bulktopus.com/
1•fer_momento•58m ago•0 comments

Contrastive Flow Matching

https://arxiv.org/abs/2506.05350
1•badmonster•1h ago•2 comments

Show HN: Posture Correction Using AirPods Motion Sensors

https://github.com/wizenheimer/workwell
4•tinylm•1h ago•0 comments

Show HN: Restore Per-App Keyboard Input Language on macOS

https://gitlab.com/spacest/InputLanguageKeeper
2•rado•1h ago•0 comments

Twilio – Intentionally Clever or Accidentally Genius?

https://ramansharma.substack.com/p/twilio-intentionally-clever-or-accidentally
2•intrepidsoldier•1h ago•0 comments

Russian billionaire: SAP replacement is expensive but essential

https://energynews.oedigital.com/energy-markets/2025/06/03/russian-billionaire-sap-replacement-is-expensive-but-essential
2•teleforce•1h ago•1 comments

Ruby Newsletter 472

https://ruby.libhunt.com/newsletter/472
1•amalinovic•1h ago•0 comments

We Built Cline to Never Hold You Hostage

https://cline.bot/blog/why-we-built-cline-to-never-hold-you-hostage
3•howtofly•1h ago•0 comments

Photoshop Arrives on Android

https://blog.adobe.com/en/publish/2025/06/03/photoshop-arrives-on-android
1•teleforce•1h ago•0 comments