mcp2 articles
Obsidian Security Hits Unicorn Status With $85M Round Targeting AI Agent Sprawl
Obsidian Security has raised $85 million in a Series D funding round at a $1.1 billion valuation, bringing its total funding to over $200 million, with the round led by Crescent Cove Advisors. The company offers a platform that governs AI agents and SaaS applications, monitoring and enforcing policies on what agents like Microsoft Copilot and Salesforce Agentforce can access and execute within enterprise systems. The new funds will be used to accelerate expansion into agentic AI security, including added governance controls for Anthropic's Claude Code and Cowork.
NadMesh Botnet Is Raiding Exposed AI Services for Cloud Keys, and the Numbers Don't Add Up
A Go-based botnet called NadMesh, discovered in early July 2025, systematically scans for exposed AI services (such as ComfyUI, Ollama, and n8n) to steal cloud credentials, Kubernetes tokens, and environment variable secrets, with the operator's own dashboard claiming over 3,800 harvested AWS keys. While the botnet prioritises AI service endpoints and MCP tools, the majority of its observed exploit traffic actually targets more traditional attack surfaces like Docker APIs and Jenkins consoles, with MCP exploitation accounting for less than 1% of recorded attempts. Defenders are urged to place exposed services behind authentication, check systems for persistence artefacts, and immediately revoke — not merely rotate — any credentials that may have been exposed.