<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Offensive-Tooling on CuraSec</title><link>https://curasec.metacog.co.kr/tags/offensive-tooling/</link><description>Recent content in Offensive-Tooling on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 17 Sep 2026 15:32:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/offensive-tooling/index.xml" rel="self" type="application/rss+xml"/><item><title>Blitzstrike: MCP penetration-testing toolbelt (634 stars)</title><link>https://curasec.metacog.co.kr/insights/2026-09-17-shinthink-blitzstrike-634/</link><pubDate>Thu, 17 Sep 2026 15:32:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-17-shinthink-blitzstrike-634/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A dedicated pen-testing framework targeting MCP (Model Context Protocol) infrastructure with 57 escalation chains signals that AI agent attack surface is maturing fast; evaluate against any MCP servers you run, but no exploitation pressure exists today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> This is a red-team framework for AI agent/MCP environments gaining rapid traction (634 stars, trending); if your estate runs MCP-based agents, build detection coverage for recon and escalation behaviors this quarter before adversaries operationalize it.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The emergence of a structured, 130-tool attack framework purpose-built for AI agent (MCP) infrastructure is a signal to get AI agent security policy in place this quarter — before controls are needed; confirm whether your engineering teams have deployed MCP servers and if a security review process exists.&lt;/li>
&lt;/ul></description></item></channel></rss>