##### Director of Research and Insights

# Greg Pollock

* [](#)
* [](https://www.linkedin.com/in/pollockgf/)
* [](#)
* [](#)
* [](#)
* [](#)

Greg Pollock is the Director of Research and Insights at UpGuard. His team performs original research on how people create problems with computers.

### Expertise

Greg Pollock is an accomplished cybersecurity researcher. He specializes in the discovery and analysis of data leaks, the identification of emerging exposure vectors in AI-driven products, and the large-scale surveying of internet infrastructure for vulnerabilities and misconfigurations.

Greg's Certified Information Systems Auditor (CISA) certification provides a formal framework for assessing information systems, directly supporting his research into how system control failures and vulnerabilities lead to data breaches.

Outside of work, Greg volunteers as a referee for youth soccer and serves on a citizen oversight committee for his local water district. He also enjoys functional woodworking and walking his dogs.

### Experience

As Director of Research and Insights at UpGuard, Greg leads initiatives that shape industry understanding of exposure trends across the digital landscape. His work combines technical analysis, data science, and narrative insight to produce authoritative research on data breaches, leaks, and global internet security posture.

Because of their significant findings, Greg's cybersecurity research is frequently featured and quoted in numerous reputable global outlets, including [The New York Times](https://www.nytimes.com/2022/07/31/business/student-privacy-illuminate-hack.html), [The Washington Post](https://www.washingtonpost.com/technology/2019/04/03/millions-sensitive-facebook-user-records-were-left-exposed-public-web-security-researchers-say/), [Forbes](https://www.forbes.com/sites/thomasbrewster/2019/01/16/massive-oklahoma-government-data-leak-exposes-7-years-of-fbi-investigations/), [Bloomberg](https://www.bloomberg.com/news/articles/2019-04-03/millions-of-facebook-records-found-on-amazon-cloud-servers), [Wired](https://www.wired.com/story/microsoft-power-apps-data-exposed/), and [CNET](https://www.cnet.com/tech/computing/millions-of-facebook-records-were-exposed-on-public-amazon-server/).

Greg’s professional experience spans cybersecurity research, data analytics, and the design of large-scale systems for detecting and visualizing network drift and configuration risk. [He holds multiple patents](https://patents.justia.com/assignee/upguard-inc) related to data leak detection and network visualization and is a Certified Information Systems Auditor (CISA).

### Education

Greg's education includes:

* M.S. in Data Science from the University of Pittsburgh
* M.A. in Literature from the University of California, Santa Cruz
* B.A. in English from James Madison University
* AYSO certified Regional youth soccer referee

## Latest from Greg Pollock

Learn more about the latest issues in cybersecurity.

[Everything Everywhere: Systemic Data Exposure in Supabase Apps](/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps)

#### [Everything Everywhere: Systemic Data Exposure in Supabase Apps](/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps)

Supabase is a favorite of AI coding agents. It's also prone to misconfiguration. We studied more than 16,000 open databases to see what's leaking.

[](/team/greg-pollock)

[Greg Pollock](#)

September 25, 2026

[Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached](/blog/cyber-resilience-act-preparedness-whos-ready-and-who-cant-be-reached)

#### [Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached](/blog/cyber-resilience-act-preparedness-whos-ready-and-who-cant-be-reached)

We surveyed 2,374 EU-registered devices and 226 listed software makers for a way to report a vulnerability. Market leaders are ready. Others, not so much.

[](/team/greg-pollock)

[Greg Pollock](#)

September 9, 2026

[Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.](/blog/oracle-just-shipped-1-449-security-patches-in-one-quarter-we-checked-how-much-of-it-is-actually-new)

#### [Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.](/blog/oracle-just-shipped-1-449-security-patches-in-one-quarter-we-checked-how-much-of-it-is-actually-new)

Oracle's July 2026 update shipped 1,449 security patches — 2.8x its all-time record. We parsed 23 quarters of advisories to find out how much is truly new.

[](/team/greg-pollock)

[Greg Pollock](#)

July 22, 2026

[Data leakage risks with DBHub MCP servers](/blog/data-leakage-risks-with-dbhub-mcp-servers)

#### [Data leakage risks with DBHub MCP servers](/blog/data-leakage-risks-with-dbhub-mcp-servers)

UpGuard found exposed DBHub servers leaking live databases to the open internet—an early sign that MCP exposure is becoming a systemic data risk.

[](/team/greg-pollock)

[Greg Pollock](#)

July 13, 2026

[Emerging Risks: Typosquatting in the MCP Ecosystem](/blog/typosquatting-in-the-mcp-ecosystem)

#### [Emerging Risks: Typosquatting in the MCP Ecosystem](/blog/typosquatting-in-the-mcp-ecosystem)

The MCP server ecosystem is susceptible to brand impersonation for both local and remote servers.

[](/team/greg-pollock)

[Greg Pollock](#)

July 2, 2026

[YOLO Mode: Hidden Risks in Claude Code Permissions](/blog/yolo-mode-hidden-risks-in-claude-code-permissions)

#### [YOLO Mode: Hidden Risks in Claude Code Permissions](/blog/yolo-mode-hidden-risks-in-claude-code-permissions)

Developers are frequently granting Claude Code permission to download, execute, and delete code, creating fertile ground for prompt injection attacks.

[](/team/greg-pollock)

[Greg Pollock](#)

January 16, 2026

[Cybersecurity Predictions for 2026: Human Risk, AI Data Leaks, and the Next Big Breach](/blog/cybersecurity-predictions-2026-human-risk-ai-data-leaks)

#### [Cybersecurity Predictions for 2026: Human Risk, AI Data Leaks, and the Next Big Breach](/blog/cybersecurity-predictions-2026-human-risk-ai-data-leaks)

Get one step ahead of the next big shock. Four security predictions for 2026—likely, uncomfortable, and easy to miss.

[](/team/greg-pollock)

[Greg Pollock](#)

July 2, 2026

[Uncovering the Shadow AI Paradox](/blog/uncovering-the-shadow-ai-paradox)

#### [Uncovering the Shadow AI Paradox](/blog/uncovering-the-shadow-ai-paradox)

Our research into the motives of shadow AI user led to surprising discoveries.

[](/team/greg-pollock)

[Greg Pollock](#)

July 2, 2026

[Downstream Data: Investigating AI Data Leaks in Flowise](/blog/downstream-data-investigating-ai-data-leaks-in-flowise)

#### [Downstream Data: Investigating AI Data Leaks in Flowise](/blog/downstream-data-investigating-ai-data-leaks-in-flowise)

A thousand Flowise instances are exposed to the internet, many of them leaking confidential business data, passwords, and more.

[](/team/greg-pollock)

[Greg Pollock](#)

July 2, 2026

[Salesforce Extortion Accelerates With New Leak Site](/blog/salesforce-leak-extortion-scatterered-lapsus-hunters)

#### [Salesforce Extortion Accelerates With New Leak Site](/blog/salesforce-leak-extortion-scatterered-lapsus-hunters)

The hacker collective Scattered Lapsus$ Hunters has launched a new leak site threatening to release data stolen from Salesforce instances.

[](/team/greg-pollock)

[Greg Pollock](#)

October 30, 2025

[Asana Discloses Data Exposure Bug in MCP Server](/blog/asana-discloses-data-exposure-bug-in-mcp-server)

#### [Asana Discloses Data Exposure Bug in MCP Server](/blog/asana-discloses-data-exposure-bug-in-mcp-server)

Asana identified a bug in its Model Context Protocol (MCP) server that may have exposed data to MCP users in other Asana accounts.

[](/team/greg-pollock)

[Greg Pollock](#)

July 2, 2026

[Open Chroma Databases: A New Attack Surface for AI Apps](/blog/open-chroma-databases-ai-attack-surface)

#### [Open Chroma Databases: A New Attack Surface for AI Apps](/blog/open-chroma-databases-ai-attack-surface)

One third of exposed instances discovered by UpGuard Research are lacking authentication. Learn how they can put your AI stack at risk.

[](/team/greg-pollock)

[Greg Pollock](#)

December 1, 2025

1 / 3

[Next](?1d3d3839_page=2)

## Cybersecurity & Risk Management Blog

Learn more about the latest issues in cybersecurity.

#### [Find Out if You're Exposed on the Dark Web](/blog/find-out-if-youre-exposed-on-the-dark-web)

Answer 5 quick questions to predict what a dark web scan will find about your company. Then run the free scan to see your real exposure.

[](/team/lance-turner)

[Lance Turner](#)

September 28, 2026

#### [12 Cybersecurity Horror Stories of 2026 (No Costume Required)](/blog/cybersecurity-horror-stories-2026)

A warning ignored once becomes a headline. Read more about these 12 real 2026 cybersecurity incidents, and the sign each one gave before it made the news.

[](/team/revashni-moodley)

[Revashni Moodley](#)

September 28, 2026

#### [The Evidence Is In: UpGuard Named a Leader in the IDC MarketScape for Worldwide Third-Party Risk Management](/blog/upguard-named-leader-in-idc-marketscape)

UpGuard has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Services 2026 Vendor Assessment. Find out why.

[](/team/cassy-van-eeden)

[Cassy van Eeden](#)

September 22, 2026

#### [Your First Dark Web Scan Report, Explained](/blog/your-first-dark-web-scan-report-explained)

You scanned your domain. What do the results mean?

[](/team/lance-turner)

[Lance Turner](#)

September 21, 2026

#### [We Researched Four AI Evidence Analysis Tools for TPRM. Here’s What We Found.](/blog/ai-evidence-analysis-tools-for-tprm)

We researched four AI evidence-parsing tools against four criteria that security teams often overlook. None nailed all four.

[](/team/cassy-van-eeden)

[Cassy van Eeden](#)

September 29, 2026

#### [Good Security Rating? Your Dark Web Exposure Says Otherwise](/blog/good-security-rating-your-dark-web-exposure-says-otherwise)

Scan your domain to see just how exposed you are on the Dark Web.

[](/team/lance-turner)

[Lance Turner](#)

September 14, 2026

[All blog posts](/blog)

## Cybersecurity & Risk Management Library

The ultimate guide to attack surface and third-party risk management – actionable advice for security teams, managers, and executives.

### [Breaches](/breaches)

Security research and global news about data breaches.

Explore resources

### [Third-party risk management](/category/third-party-risk-management)

Articles, news, and research on third-party risk management.

Explore resources

### [Attack Surface Management](/category/attack-surface-management)

Articles, news, and research on attack surface management.

Explore resources

### [Cybersecurity](/category/cybersecurity)

Articles, news, and research on cybersecurity.

Explore resources

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
