
Threat Talks · 2025-11-11 · 35 min
The new AI app store is here - and it’s already making choices for your company. This episode shows you how to spot it, stop it, and stay safe. Host Lieuwe Jan Koning with RobMaas (Field CTO, ON2IT) explain the app store nightmare in plain language. A new system (MCP) lets AI tools like ChatGPT , Claude , and Gemini do tasks for you - sometimes too much. When a bad tool or a sneaky document gets in, it can read, send, or delete things without you noticing. Real cases, real damage: Postmark MCP backdoor - secretly BCC’d emails (email copies) Shadow Escape - “zero-click” data theft from a hidden prompt kubectl chaos - a command mistake that can wipe servers Your quick fix: keep a list of every AI tool and give each only the access it needs. Example: let your document bot read just the “Policies” folder - not your whole drive. For more fixes, watch the full episode.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.