{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Threat Talks - Your Gateway to Cybersecurity Insights","title":"The App Store Nightmare: Why AI MCP Stores Are a Trap","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/58a76c2a\"></iframe>","width":"100%","height":180,"duration":2101,"description":"The new AI app store is here - and it’s already making choices for your company.\nThis episode shows you how to spot it, stop it, and stay safe.\nHost Lieuwe Jan Koning with RobMaas (Field CTO, ON2IT) explain the app storenightmare in plain language. A new system (MCP) lets AI tools like ChatGPT, Claude, and Gemini do tasks for you - sometimes too much. When a bad tool or a sneaky document gets in, it can read, send, or delete things without you noticing.\n\nReal cases, real damage:\nPostmark MCP backdoor - secretly BCC’d emails (email copies)\nShadow Escape - “zero-click” data theft from a hidden prompt\nkubectl chaos - a command mistake that can wipe servers\n\nYour quick fix: keep a list of every AI tool and give each only the access it needs. Example: let your document bot read just the “Policies” folder—not your whole drive. For more fixes, watch the full episode.\nKey topics covered:\n·       The app storenightmare: a new AI app store you don’t control\n·       How a tricked document can make your AI act against you\n·       A simple ZeroTrust plan anyone can start today\n·       How to cut tool sprawl, cost, and risk—without slowing the team\n\nIf you use ChatGPT, Claude, or Gemini at work, this is your survival brief.\nSubscribe for more Threat Talks and ON2IT’s Zero Trust guidance.\n \nGuest and Host Links: \nRob Maas (Field CTO, ON2IT): https://www.linkedin.com/in/robmaas83/ \nLieuwe Jan Koning (Founding Partner, ON2IT): https://www.linkedin.com/in/lieuwejan/ \n\n\nAdditional Resources:\nThreat Talks: https://threat-talks.com/\nON2IT (Zero Trust as a Service): https://on2it.net/\nAMS-IX: https://www.ams-ix.net/ams\nAnthropic MCP announcement: https://www.anthropic.com/news/model-context-protocol\nOpenAI Tools/Connectors/MCP: https://platform.openai.com/docs/guides/tools-connectors-mcp\nKubernetes (kubectl): https://kubernetes.io/docs/reference/kubectl/\nReported Postmark MCP backdoor: https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html\nShadow Escape zero-click...","thumbnail_url":"https://img.transistorcdn.com/zxiRQtIn39fLuEqIC458HdYTjdufBy-QMdJtCYFz97Y/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xN2Q1/NGE1NjBhYWY0ZmY5/NzEyODA5OGU3NDdi/MmNmYi5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}