Noma Security A.I CyberSecurity Scoring
Noma Security
Company Information
Website:https://noma.security
Employees number:109
Number of followers:8,735
NAICS:541514
Industry Type:Computer and Network Security
Homepage:noma.security
Noma Security Risk Score (AI oriented)
Between 700 and 749
Noma SecurityComputer and Network Security
Updated:
30/07/2026
30/07/2026
746/1000
Moderate
Ba
Noma Security Global Score (TPRM)
xxxx
Noma SecurityComputer and Network Security
Score locked

Noma SecurityModerate
Current Score
746Ba (MODERATE)
01000
2 incidents
-3.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
746
JULY 2026
751
Vulnerability
01 Jul 2026 • Noma Security
Ruflo: Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
Critical Ruflo AI Agent Flaw Exposes Enterprises to Full System Takeover
745
CRITICAL-6
NOM1785422646
Critical Ruflo AI Agent Flaw Exposes Enterprises to Full System Takeover
Researchers at Noma Security have uncovered a critical vulnerability (CVE-2024-XXXX, CVSS 10.0) in Ruflo, an open-source AI agent platform, allowing unauthenticated attackers to hijack enterprise AI environments with a single HTTP request. The flaw, dubbed RufRoot, affects Ruflo versions prior to 3.16.3 and stems from an exposed Model Context Protocol (MCP) bridge, which serves as the platform’s central control interface.
### How the Attack Works
The MCP bridge, an Express.js server, handles all AI agent tool invocations including shell commands, database operations, and memory storage without requiring authentication. In a proof-of-concept, researchers demonstrated:
- Remote code execution via Ruflo’s `terminal_execute` tool.
- Theft of LLM API keys from environment variables.
- Deployment of attacker-controlled AI agent swarms.
- Access to user conversations stored in MongoDB.
- AI memory poisoning by injecting malicious entries into Ruflo’s AgentDB, enabling persistent influence over future AI responses.
The vulnerability was validated against a default Ruflo deployment on AWS EC2, confirming its exploitability in real-world environments.
### Broader Implications for AI Security
While the flaw is specific to Ruflo, security experts warn it highlights systemic risks in AI orchestration platforms:
- MCP adoption has outpaced security defaults, with many tools prioritizing ease of setup over authentication.
- Persistent AI memory a writable data store is rarely treated as a security boundary, allowing attackers to embed malicious instructions undetected.
- Network boundary assumptions fail when AI agents are deployed on corporate-accessible servers.
### Mitigation and Response
Ruflo has released version 3.16.3, which binds the MCP bridge to the loopback interface by default and enforces authentication. Noma Security recommends immediate actions for affected organizations:
- Close firewall access to ports 3001 (MCP Bridge) and 27017 (MongoDB).
- Rotate all LLM API keys and audit AgentDB for malicious entries (patching alone does not remove poisoned memory).
- Inspect MongoDB for tampering.
The disclosure follows responsible reporting to Ruflo, which issued a public security advisory alongside the fix. The incident underscores the need for strict access controls, memory audits, and credential rotation in AI agent deployments.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
751
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
750
Vulnerability
08 Dec 2025 • Noma Security
Noma Security: Google Fixes Gemini Enterprise Flaw That Exposed Corporate Data
GeminiJack: Zero-Click Vulnerability in Google Gemini Enterprise Leading to Corporate Data Leaks
749
CRITICAL-1
NOM1765375786
Google Patches Zero-Click Vulnerability in Gemini Enterprise Exposing Corporate Data
In June 2025, security researchers at Noma Security uncovered a critical zero-click vulnerability in Google Gemini Enterprise, dubbed GeminiJack, which could enable attackers to exfiltrate sensitive corporate data without user interaction. The flaw, reported to Google the same day, affected Gemini Enterprise—Google’s suite of AI-powered workplace tools—and Vertex AI Search, a Google Cloud platform for AI-driven search and recommendations.
The vulnerability stemmed from an indirect prompt injection weakness in Gemini’s Retrieval-Augmented Generation (RAG) architecture, which allows the AI to query across multiple Google Workspace data sources (Gmail, Google Docs, Calendar, etc.). Attackers could embed malicious instructions in seemingly benign documents, emails, or calendar events. When a legitimate employee performed a routine search, the AI would unknowingly process these instructions, scan authorized Workspace data for sensitive terms, and transmit the results to an attacker-controlled server via an external image URL—all while bypassing traditional security controls.
The attack required no user interaction, making it particularly stealthy. Google confirmed the report in August 2025 and collaborated with Noma Security to remediate the issue. By December, Google had deployed updates that separated Vertex AI Search from Gemini Enterprise, eliminating shared LLM workflows and RAG capabilities. However, Noma Security warned that such vulnerabilities may persist as AI systems gain broader access to corporate data, outpacing the detection capabilities of conventional security tools.
The UK’s National Cyber Security Centre (NCSC) has since released guidance to help organizations mitigate prompt injection risks, underscoring the growing threat posed by AI-driven data exfiltration. The incident highlights the expanding attack surface introduced by corporate AI adoption, where a single flaw can expose vast amounts of sensitive information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Noma Security ??
What was Noma Security's A.I Rankiteo Cyber Score in July 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in June 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Noma Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Noma Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Noma Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Noma Security's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Noma Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Noma Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Noma Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?