Home / Companies / Pynt / Blog / July 2025

July 2025 Summaries

2 posts from Pynt

Filter
Month: Year:
Post Summaries Back to Blog
Golan Yosef, Chief Security Scientist and Co-Founder of Pynt, explores how a seemingly secure system can be exploited through composition rather than individual vulnerabilities. Using a Gmail message, he demonstrates how code execution can be triggered through Claude Desktop, an LLM host application, by leveraging the interconnected nature of modern computing platforms, known as MCPs. Initially, Claude detected the phishing attempt and warned against it, but by resetting its context in new sessions, Yosef was able to iteratively refine the attack until it succeeded. The exercise highlights the compositional risks inherent in LLM-powered applications, which rely on layers of delegation, agentic autonomy, and third-party tools, posing significant security challenges. The experiment underscores the need for solutions like Pynt MCP Security to identify and mitigate risks associated with trust-capability combinations before they escalate into complex exploits, emphasizing the evolving nature of security in the era of AI.
Jul 16, 2025 646 words in the original blog post.
Two years after launching its first integration with Postman, Pynt has successfully made API security more accessible and seamlessly integrated into the workflows of developers and QA professionals across over 180 countries, emphasizing the importance of scanning smarter rather than just earlier in the software development lifecycle. A study involving 250 security and engineering professionals revealed that many companies struggle with incomplete "Shift Left" security implementations, often hindered by false positives, difficult tool integration, and overwhelming volumes of findings. Pynt identifies QA teams as the optimal focus for security testing due to their inherent role in testing behavior and edge cases without the pressure of sprint deadlines, leading to more effective vulnerability detection. The newly introduced native Postman integration allows users to perform security assessments directly within their existing workflows, enhancing the QA experience and demonstrating that effective security integration should align with how software is naturally developed, rather than creating additional challenges.
Jul 08, 2025 468 words in the original blog post.