Skip to main content

authors

Eunjee Choi

Eunjee Choi articles and resources from Pomerium.

Eunjee Choi

Topic archive

More from Eunjee Choi

September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears
blog posts

September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears

September was a month of contrasts for the Model Context Protocol (MCP). On the one hand, the ecosystem matured rapidly. On the other hand, a wave of reports underscored how quickly attackers are targeting these interfaces. Researchers warned of prompt‑injection attacks, backdoored packages and a raft of newly ranked vulnerabilities, while practitioners called for stronger identity flows, fine‑grained authorization and tighter governance.

August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth
blog posts

August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth

August was filled with vulnerabilities and developments in the agentic AI and Model Context Protocol (MCP) landscape. Multiple high‑severity remote‑code‑execution vulnerabilities demonstrated how easily malicious servers or modified configurations can hijack developer machines. Docker went so far as to label the MCP ecosystem a “security nightmare,” prompting calls for OAuth 2.1 authorization and zero‑trust practices. Meanwhile, vendors made notable releases and thought leaders explored the future of AI as adoption accelerates.

July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth
blog posts

July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth

A number of pivotal developments marked the agentic AI and Model Context Protocol (MCP) world this past July. Two critical remote‑code‑execution flaws, one in the widely used mcp‑remote tool and another in Anthropic’s MCP Inspector , highlighted the growing security risks of AI‑agent tooling. Meanwhile, vendors released new MCP servers and training programs, and the open‑source project announced a formal governance model to sustain its rapid growth. The compiled July headlines below capture both the promise and the perils of the evolving MCP ecosystem.

June 2025 MCP Content Round-Up: Incidents, Updates, Releases, and more!
blog posts

June 2025 MCP Content Round-Up: Incidents, Updates, Releases, and more!

It’s been a busy month in the world of Model Context Protocol (MCP). Between new open source server releases, security leaks, and insightful commentary from developers building on top of these tools, there’s a lot to keep up with—and even more to think about if you're working on or around AI agents. But, one thing is clear: MCP is here, and it needs to be secured .

5 Actionable Zero Trust Patterns from NIST SP 1800-35 (and How to Implement Them)
blog posts

5 Actionable Zero Trust Patterns from NIST SP 1800-35 (and How to Implement Them)

Implementing a Zero Trust Architecture (ZTA) is no longer a task that can be pushed to tomorrow—it's best practice to begin implementing it today. Understanding that moving from theory to practical implementation can be challenging, the National Institute of Standards and Technology (NIST) published Special Publication 1800-35 to provide real-world, actionable patterns to guide organizations through their Zero Trust journeys.

May 2025 Data Breaches: 184M Passwords, 364K SSNs Leaked
blog posts

May 2025 Data Breaches: 184M Passwords, 364K SSNs Leaked

Cyber attacks showed no signs of slowing down this past May 2025, with high-profile breaches and settlements making headlines. While the root causes behind many of these breaches remain undisclosed, a familiar pattern persists: insufficient access controls, third-party exposures, and delayed detection. These recurring weaknesses highlight the continued urgency for organizations to adopt zero-trust security principles—designed to prevent lateral movement, minimize damage, and detect anomalies before it’s too late.

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements
blog posts

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements

Cyber attacks didn’t slow down this past April 2025, recording sizable breaches and settlements—one data breach compromised the personal identifiable data of 4 million individuals. The cause behind many of these breaches was undisclosed, however, there is a recurring theme of insufficient access controls, third-party vulnerabilities, and delayed breach detection—all weaknesses that zero-trust security measures could have addressed.

March 2025 Data Breaches: 5M+ Impacted, $39.9M+ in Damages
blog posts

March 2025 Data Breaches: 5M+ Impacted, $39.9M+ in Damages

March 2025 saw yet another wave of significant cyber incidents affecting organizations across industries, with over 5 million individuals impacted and damages exceeding $39.9 million from just three settlements alone. These breaches reinforce a crucial reality: successful attacks rarely require sophisticated tactics, but instead exploit widespread gaps in basic security measures.

Context-Based Access Control and Zero Trust: Key Insights from the CSA White Paper
blog posts

Context-Based Access Control and Zero Trust: Key Insights from the CSA White Paper

The Cloud Security Alliance (CSA) recently released a white paper on Context-Based Access Control (CBAC) and its role in advancing Zero Trust security models. The paper underscores the necessity of shifting from static, trust-based access control to real-time, adaptive authentication that evaluates risk dynamically, and Pomerium was highlighted as a key player in the CBAC space.

January 2025 Data Breaches [LIST]
blog posts

January 2025 Data Breaches [LIST]

According to the 2024 Annual Data Breach Report by the Identity Theft Resource Center, there were more than 1.7 million victim notices, “a measure of the scale of events and impacts on individuals,” last year, a number that was triple that of 2023. With 3,158 total compromises recorded in 2024, it’s no surprise that this past January 2025 was also full of data breaches.

The New Frontier: AI Companies Require New Approaches to Security
blog posts

The New Frontier: AI Companies Require New Approaches to Security

AI companies are fundamentally different, and the industry is unlike anything we’ve seen before. While there are surface-level similarities to other high-tech organizations in how they operate (e.g. commonalities like Kubernetes, cloud-native architectures, and a reliance on everything-as-code), the reality is far more nuanced. AI companies face evolving and unprecedented challenges and dynamics that make their security and operational needs fundamentally different from those of other industries.

What is a "Pomerium"?
blog posts

What is a "Pomerium"?

When I first started developing the idea for Pomerium, choosing the name wasn’t just an afterthought—it was a deliberate decision to align the company’s mission with a concept that’s both historically significant and deeply relevant to the challenges of modern cybersecurity.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo