{"data":{"id":"325f3b1a-7700-4b84-a16b-8f0f2101ab8c","title":"Top MCP security resources — October 2026","summary":"This is a news digest of 15 MCP security resources for October 2026. It highlights an authentication bypass in LiteLLM's MCP endpoint, which accepts any invalid bearer token (CVE-2026-59822) and is now on CISA's Known Exploited Vulnerabilities list, and session ID spoofing in the Grafana MCP server, which lets unauthenticated callers invoke tools with the server's service account credentials.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://adversa.ai/blog/top-mcp-security-resources-october-2026/","publishedAt":"2026-10-08T09:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["jailbreak","supply_chain"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Anthropic","Google","Microsoft","Amazon"],"affectedVendorsRaw":["MCP","LiteLLM","Grafana MCP server","Obot MCP gateway","MCP Python SDK","Amazon Quick","CoSAI MCP security model 2.0"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-08T09:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}