【Dear Utol (2025): Aswang Episode 30】
A bug in one of Asana's new AI features made user information accessible to other users for several weeks.
The Dear Utol (2025): Aswang Episode 30company said the issue was resolved and it was not the result of a malicious hack. Instead, it appeared to be a logic flaw in its MCP (Model Context Protocol) server that was released on May 1, according to cybersecurity firm UpGuard (via BleepingComputer).
MCP is an open-source framework that enables AI assistants to interact with sites and apps. The introduction of Asana's MCP Server enabled companies to integrate AI features like summarization and natural language search from LLMs.
You May Also Like
SEE ALSO: 'Your Year in Asana' is a reminder of all the work you did (or didn’t do)
The rise of generative AI tools and new standards that enable interoperability for LLMs create new privacy issues and increased cybersecurity risk. MCP servers are a shiny new target for hackers, and there's also risk of prompt injection attacks, token theft, and a general increase in data leaks since MCPs request broad permission to function smoothly, according to a blog post from cybersecurity firm Pillar.
According to UpGuard, the bug "appears to have been part of this initial release," and was discovered by Asana on June 4. But during this time, Asana users working with the MCP server have been able to access information from other accounts' "projects, teams, tasks, and other Asana objects," according to an email reportedly sent to customers impacted.
In a statement to BleepingComputer, Asana said the bug impacted around 1,000 accounts. Asana has more than 130,000 companies using its project management platform, including some big companies like Uber, Spotify, and Airbnb. (Disclosure: Mashable's editorial team also uses Asana.)
Asana took the server offline and informed customers using the MCP server on June 16 about the bug. "As soon as the vulnerability was discovered, our teams immediately took the MCP server down and resolved the issue in our code," Asana said in its statement to BleepingComputer. Meanwhile, the company sent a contact form to customers potentially impacted to compile a full report of which companies may have had their data exposed.
It's unclear yet if there was any major data breach, but Asana advised companies to review their logs for MCP access and any information generated by their AI tools and report it to Asana if they find any data that doesn't belong to their company.
UPDATE: Jun. 18, 2025, 1:50 p.m. EDT Asana confirmed in a status update that the affected server was back online as of June 17.
Topics Cybersecurity Privacy
Search
Categories
Latest Posts
Mary Shows Up
2025-06-26 04:23How to unblock Xnxx for free
2025-06-26 04:09A guide to cellphones built for kids
2025-06-26 02:46Is it 'Thunderbolts*' or *The New Avengers'?
2025-06-26 02:33Popular Posts
Against Fear
2025-06-26 05:13Best robot vacuum deal: Save $200 on Eufy X10 Pro Omni robot vacuum
2025-06-26 05:08How to unblock Pornhub for free in Alabama
2025-06-26 04:48Switch to Verizon home internet, get a free Nintendo Switch
2025-06-26 03:08The Best Gaming Concept Art of 2016
2025-06-26 02:49Featured Posts
Best speaker deal: Save $30 on the JBL Clip 5
2025-06-26 04:51Best Samsung deal: Save $140.99 on Samsung Galaxy Watch 6
2025-06-26 04:48NYT Strands hints, answers for June 3
2025-06-26 04:43What is Palantir? The secretive tech company working with Trump
2025-06-26 02:41Google Pixel Buds Pro 2: $40 off at Amazon
2025-06-26 02:29Popular Articles
Apple is actively looking at AI search for Safari
2025-06-26 05:04Best Apple deal: Save $100 on Apple Watch Series 10 (GPS, 42mm)
2025-06-26 04:46Today's Hurdle hints and answers for June 5, 2025
2025-06-26 03:57Best soundbar deal: Save $200 on the Bose Smart Ultra Soundbar
2025-06-26 03:29Hurricane Laura's impact lingered with nightmarish mosquito swarms
2025-06-26 03:10Newsletter
Subscribe to our newsletter for the latest updates.
Comments (9933)
New Knowledge Information Network
Amazon Prime Grubhub deal: Save $10 off orders of $20 or more
2025-06-26 05:05Mark Information Network
Keys vs. Gauff 2025 livestream: Watch French Open for free
2025-06-26 03:55Mark Information Network
Get the Eufy P2 Pro Digital Bathroom Scale for 50% off at Amazon
2025-06-26 03:27Fun Fight Information Network
Prison Architect: One of 2013's Most Interesting PC Games
2025-06-26 02:55Star Sky Information Network
NYT Connections Sports Edition hints and answers for May 19: Tips to solve Connections #238
2025-06-26 02:48