Skip to content

Official Azure MCP exploited to steal users Keyvaults secrets

tramlines.io
4 pointscoderinsan1 comment
On HN

Comments

Tramlines.io presents: Another day, another official MCP server exploited. Again.

Why on earth does Azure need an MCP server? MCPs do not belong anywhere near a critical system responsible for storing sensitive secrets or env vars.

Now the official Azure MCP server can be breach with all your key-vault secrets exfiltrated.

I think this tells you that "MCP" is rising to becoming the worst protocol standard that has ever been designed.

And once again, no-one cares. (they really should)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.