Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
Unsafe defaults in MCP configurations open servers to possible remote code execution, according to security researchers who ...