CRITICAL
Senior PM's personal ChatGPT, pasting strategy docs
Three times a day for the past two weeks. Account ties to a private email; prompts sit in the training-eligible tier.
▸ Detected via endpoint sensor
CRITICAL
Bedrock agent in a dev account with prod credentials
Spun up during a hackathon in March, never decommissioned. Read access to production buckets including customer PII.
▸ Detected via cloud scan
HIGH
MCP server with `filesystem:write` added last Tuesday
Internal MCP that previously had read-only access. PR approved without flagging the permission expansion.
▸ Detected via code scan + drift comparison
HIGH
Cursor session reading from `customer-data-prod`
An engineer's Cursor instance has been reading customer records for the past week. Prompts cached in the provider's training-eligible tier.
▸ Detected via endpoint sensor
MEDIUM
Self-hosted Llama-3 with no authentication
Deployed to an instance during a POC. Anyone in the VPC can hit the endpoint. No rate limit; no audit log.
▸ Detected via cloud scan
MEDIUM
Third-party MCP server with no data-processing agreement
A team plugged in a vendor MCP that proxies through an unknown infrastructure provider. Not on the approved-vendor list.
▸ Detected via runtime telemetry