A bug in one of Asana's new AI features made user information accessible to other users for several weeks.
The Watch Hollywood Sex Fantasy (2001)company said the issue was resolved and it was not the result of a malicious hack. Instead, it appeared to be a logic flaw in its MCP (Model Context Protocol) server that was released on May 1, according to cybersecurity firm UpGuard (via BleepingComputer).
MCP is an open-source framework that enables AI assistants to interact with sites and apps. The introduction of Asana's MCP Server enabled companies to integrate AI features like summarization and natural language search from LLMs.
The rise of generative AI tools and new standards that enable interoperability for LLMs create new privacy issues and increased cybersecurity risk. MCP servers are a shiny new target for hackers, and there's also risk of prompt injection attacks, token theft, and a general increase in data leaks since MCPs request broad permission to function smoothly, according to a blog post from cybersecurity firm Pillar.
According to UpGuard, the bug "appears to have been part of this initial release," and was discovered by Asana on June 4. But during this time, Asana users working with the MCP server have been able to access information from other accounts' "projects, teams, tasks, and other Asana objects," according to an email reportedly sent to customers impacted.
In a statement to BleepingComputer, Asana said the bug impacted around 1,000 accounts. Asana has more than 130,000 companies using its project management platform, including some big companies like Uber, Spotify, and Airbnb. (Disclosure: Mashable's editorial team also uses Asana.)
Asana took the server offline and informed customers using the MCP server on June 16 about the bug. "As soon as the vulnerability was discovered, our teams immediately took the MCP server down and resolved the issue in our code," Asana said in its statement to BleepingComputer. Meanwhile, the company sent a contact form to customers potentially impacted to compile a full report of which companies may have had their data exposed.
It's unclear yet if there was any major data breach, but Asana advised companies to review their logs for MCP access and any information generated by their AI tools and report it to Asana if they find any data that doesn't belong to their company.
UPDATE: Jun. 18, 2025, 1:50 p.m. EDT Asana confirmed in a status update that the affected server was back online as of June 17.
Topics Cybersecurity Privacy
Death of a Salesman by Sam SweetGab's failed attempt at cleverness becomes the most hilarious selfWhat is pelvic pain and what can you do to treat it?Away from Her by Sadie SteinLogan Paul, now an intellectual, says he's done with HollywoodThreads app already struggles with moderating misinformation and hate speech, advocates warnEvergreen by Sadie SteinThe History of Letters of Note, and Other News by Sadie SteinNew stimulus checks are coming and the internet is celebrating accordinglyAwards Season Fever! And Other News by Sadie SteinThe Diary Diaries by Simon AkamDeath of a Salesman by Sam SweetFran Drescher warns of of humans 'replaced by machines' in SAG strike announcementCatch nearly 100 Prime Day deals that are still liveHistory Boys by Sadie SteinThe All Star Game proves the NBA isn't a 'moral' pro sports leagueUK horrified by all the U.S. drug ads during Meghan Markle interview'Quordle' today: See each 'Quordle' answer and hints for July 14Musk admits Twitter cash flow is still negative, lost 50% of ad revenueTurkey in a Suitcase by J. D. Daniels In Memoriam: The tech that died in 2025 (so far) FunkyFrogBait left their career as a software engineer for YouTube. It paid off. 10 Tech Enthusiast Guilty Pleasures Honduras vs. El Salvador 2025 livestream: Watch Concacaf Gold Cup for free The 5 best smartphones of 2025 so far Jools Lebron, Ruba Wilson, and more come together to discuss being LGBTQ creators. The rise of YouTube: 20 years of creators, culture, and content at VidCon Senate upholds ban on State AI laws in Trump's budget bill Today's Hurdle hints and answers for June 22, 2025 The 'Nintendo Switch 2 Welcome Tour' is definitely worth $10 Yes, 16 billion passwords leaked. No, it's not what you think. OtterBox 15W MagSafe wireless charging stand: $14.95 Cost Per Frame Analysis: The Best Graphics Cards in Mid 2025 Best Apple deal: Apple AirPods 4 for under $100 at Amazon Android 16: These 6 features are worth the update Mikey Angelo's 3 essential tools for creating viral content Wordle today: The answer and hints for June 21, 2025 How to make a hook in a TikTok video 3 tips for creating viral content from the creators who get it done NYT Connections hints and answers for June 22: Tips to solve 'Connections' #742.
2.0792s , 8202.3984375 kb
Copyright © 2025 Powered by 【Watch Hollywood Sex Fantasy (2001)】,Miracle Information Network