Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
91 items
Straiker Wins 2026 CyberSecurity Breakthrough Award for Cybersecurity Solution of the Year for Artificial Intelligence
Oct 9, 2026InfoNewsIndustryStraiker, an agentic AI security company, announced on October 9, 2026 that it was named "Cybersecurity Solution of the Year for Artificial Intelligence" in the 2026 CyberSecurity Breakthrough Awards. Its platform has three capabilities: Discover AI for visibility into AI agents, MCP servers, Agent Skills, tools, and connections; Ascend AI for autonomous adversarial testing of prompt injection, tool misuse, and data exfiltration; and Defend AI for real-time runtime protection with an agentic kill switch to contain compromised agents.
Straiker BlogTop MCP security resources — October 2026
Oct 8, 2026MediumNewsSecurityIndustryThis is a news digest of 15 MCP security resources for October 2026. It highlights an authentication bypass in LiteLLM's MCP endpoint, which accepts any invalid bearer token (CVE-2026-59822) and is now on CISA's Known Exploited Vulnerabilities list, and session ID spoofing in the Grafana MCP server, which lets unauthenticated callers invoke tools with the server's service account credentials.
Adversa AI BlogEndor Labs + SpaceXAI: Securing every stage of agentic software delivery | Blog | Endor Labs
Oct 6, 2026InfoNewsSecurityIndustryEndor Labs and SpaceXAI are partnering to secure agentic software delivery on Grok Build, from the first tool call to merged pull requests. Endor Labs checks code and dependencies as agents produce them and fixes issues before they leave the session. The integration started with a free MCP server, added a hooks integration in December 2025 that scans every package an agent installs, added Coding Agent Governance in May 2026, and added the Endor Labs Agent Kit in June.
Endor Labs BlogStraiker in Gartner® 2026 AI Cybersecurity Impact Radar
Oct 6, 2026InfoNewsIndustrySecurityGartner's Emerging Tech Impact Radar: AI Cybersecurity Ecosystem lists Straiker as a Sample Vendor in two categories: AI Security Testing and AI Security Platforms. Straiker says these reflect a shift toward continuously attacking AI systems to find weaknesses and using those findings to protect them in production. The source ties this to agentic AI, where testing must cover MCP servers, tools, and database access, not only model prompts.
Straiker BlogWelcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Oct 6, 2026MediumNewsSecurityIndustryOX Security researcher Moshe Siman Tov Bustan reports on an analysis of 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames. The study found 15.6% of hostnames resolve outside the United States, 0.45% route traffic through consumer tunneling services such as ngrok-free, and 2.3% no longer resolve, with six on expired domains that anyone can register.
The Hacker NewsOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Sep 29, 2026MediumNewsSecurityIndustryA malicious MCP server can trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to a token endpoint the attacker controls. Affected versions are 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and the flaw is rated 7.5 for non-interactive providers and 6.5 for the interactive provider. Cycode reported the issue, and no CVE had been assigned as of September 29, 2026.
Fix: Upgrade to 1.30.0 on the 1.x line or 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, also pass issuer= to name the login service the credentials belong to, since upgrading alone does not fix those providers. Replace the deprecated RFC7523OAuthClientProvider, which has no issuer= option, with one of the other providers. After upgrading, clear stored OAuth client registrations once. If a client may have connected to an untrusted server, rotate its client secret and revoke its tokens at the login service. On older versions, connect only to MCP servers you trust.
The Hacker NewsCan We Control Every AI Agent Before It Becomes Our Next Privileged Insider?
Sep 24, 2026InfoNewsSecurityIndustryAI agents are spreading into enterprises faster than many security programs were built to handle. They read email, access SaaS applications, query databases, invoke APIs, use MCP tools and modify records. The source text is cut off before it describes any specific controls.
Check Point ResearchWorkforce AI Security Policy Management Is Now Conversational
Sep 23, 2026InfoNewsIndustrySecurityCheck Point has released the Workforce AI MCP, its own Model Context Protocol server for Workforce AI Security. Connecting a compatible AI client lets administrators query, analyze and manage employee AI usage policy in natural language rather than through filters, screens and individual rule checks. The server covers users, managed assets, GenAI application usage, DLP data types, and agent and MCP activity within a single conversation.
Check Point ResearchCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Sep 22, 2026MediumNewsSecurityIndustryJFrog Security Research's Yuval Moravchick found CVE-2026-90898 (CVSS 9.8) in Bifrost, an open-source AI gateway. Before 2.1.0 with management authentication disabled, which is the default, a single unauthenticated POST to /api/mcp/client registers a stdio MCP client, and Bifrost runs the specified command as the gateway process user before any MCP handshake. Because the gateway stores API keys for every connected provider, the attacker gains access to those credentials.
Fix: Upgrade to transports/v2.1.0, which returns 403 for unauthenticated stdio MCP client registration. If upgrading is not immediately possible, set governance.auth_config.is_enabled to true, use strong credentials, and keep the management listener off untrusted networks. JFrog advises treating any instance that ran with authentication disabled and an exposed management API as compromised and rotating virtual keys and provider API keys.
The Hacker NewsGoogle will now let any AI agent run your smart home
Sep 16, 2026InfoNewsIndustrySecurityGoogle is opening its smart home platform to third-party AI agents through a new Google Home MCP integration. The integration lets agents that support the Model Context Protocol, including Claude and Open Claw, control and monitor connected devices and access event history.
The Verge (AI)AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
Sep 3, 2026InfoNewsSecurityIndustryAIR Security has emerged from stealth with $50 million in funding, led by Sequoia Capital and Greenoaks, for a firewall that protects AI agents. Its research found more than 17,800 public AI add-ons (6.7M installations) relying on untrusted external instruction sources, and AI Skills impersonating Anthropic and OpenAI. The firewall screens skills, plugins, MCP servers and add-ons before and after deployment and can revoke them organization-wide.
SecurityWeekAIR raises $50M to help companies vet the skills and add-ons AI agents use
Sep 1, 2026InfoNewsSecurityIndustryAI security startup AIR has come out of stealth with $50 million raised across two seed rounds, led by Sequoia and Greenoaks, to build a product that monitors the supply chain of skills, plug-ins, MCP servers and add-ons used by AI agents. The platform discovers agents running in a company, vets their tools against a whitelist AIR maintains, and blocks those that fail security criteria. AIR says its platform currently filters out about 27% of the add-ons and skills it finds online.
TechCrunch (Security)CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
Sep 1, 2026InfoNewsIndustrySecurityCrowdStrike is introducing Falcon Guardian, the evolution of Falcon AI Detection and Response (AIDR), to secure AI agents at runtime on Windows, macOS and Linux endpoints. The product discovers known and unknown agents and fuses their prompts, tool calls and MCP server use with endpoint telemetry to link prompts to downstream system actions. It also adds an AI gateway and extends MDR and cross-domain threat hunting to the platform.
CrowdStrike BlogSecuring Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Aug 31, 2026InfoNewsSecurityIndustryClaude Code runs file reads, shell commands and MCP tool calls on developers' machines, where the harness, not the LLM, executes actions and holds the credentials. Anthropic's new Compliance API endpoints give security teams a clearer view of that local activity, but the article argues activity logs alone cannot show whether an agent's access is legitimate. Token Security reports that local agents account for 68.6% of the AI agents it discovers in customer environments.
The Hacker NewsInside 90 days of attacks on AI infrastructure
Aug 27, 2026MediumNewsSecurityIndustryWiz Threat Research reports 90 days of attack telemetry from honeypots imitating AI and ML services, including LiteLLM, Flowise, LangChain, Langflow, ChromaDB and Ollama. Attackers exploited an authentication bypass in LiteLLM's MCP Gateway (CVE-2026-59822), where a failed OAuth2 token check returns an unrestricted UserAPIKeyAuth() object, so any Bearer token grants full MCP access. They also abused a command injection in the MCP server test endpoints (CVE-2026-42271) to run a cryptominer, which is listed in CISA KEV as of June 2026.
Wiz Research BlogExtend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK
Aug 27, 2026InfoNewsSecurityIndustryAmazon Bedrock Guardrails validates model inputs and outputs, but data that flows through tool calls, external data sources and MCP servers sits outside the model boundary. The article proposes three validation checkpoints built with Strands Agents SDK lifecycle hooks and Amazon Bedrock guardrails to extend coverage to those trust boundaries without changing existing tools or agent logic. The first checkpoint, inbound data validation, uses a BeforeInvocationEvent hook to block policy-violating content before it reaches the model.
Fix: The source describes three validation checkpoints implemented with Strands Agents SDK lifecycle hooks (Checkpoint 1: inbound data validation using a BeforeInvocationEvent hook; Checkpoint 2: tool interaction supervision using a BeforeToolCallEvent hook; Checkpoint 3 is not visible in the excerpt), and scoping guardrails to specific tools. The excerpt does not state a patch or fixed version.
AWS Security BlogMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Aug 25, 2026MediumNewsSecurityIndustryMarimo fixed a high-severity code injection flaw, CVE-2026-75149, in its notebook software affecting versions prior to 0.23.15. A crafted notebook can supply an attacker-controlled MCP server command through notebook configuration, and the command runs as a local subprocess when the victim opens the notebook in edit mode, before any cell executes. The CNA record assigns CVSS v4 8.7 and CVSS v3.1 8.8, requiring user interaction.
Fix: Marimo has addressed the issue in version 0.23.15. Users running an affected release should move to a version outside the affected range. Marimo's PEP 723 hardening patch treats notebook metadata as attacker-controlled and passes notebook-supplied configuration through an allowlist that removes the ai, mcp, completion, secrets and server sections.
The Hacker NewsHow MCP Servers Can Expose Enterprise Secrets
Aug 17, 2026InfoNewsSecurityIndustryMCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams know the server is running. The MCP server sits between an AI agent and enterprise systems, so it typically holds credentials such as service account keys, API tokens and other secrets for every system it touches.
The Hacker NewsMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Aug 11, 2026MediumNewsSecuritySafetyASSET Research Group disclosed GhostSplice, a technique in which a malicious MCP server splits a data-theft request across a tool description, a tool result and a later project-scan result, so AI coding agents assemble and send SSH keys, environment secrets, source code and customer data to the attacker's tool. Tests in isolated projects with fake credentials reported average compliance rising from 42% to 82% across eleven API-tested models when the request was split in two. The source text says the attack assumes the developer has already connected the attacker's MCP server and that the agent can read the target files.
Fix: The source text does not state a fix or patch, but says the defense lands on the client: the MCP specification says clients should keep a human able to deny tool invocations and must treat annotations from untrusted servers as untrusted.
The Hacker NewsVeeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Aug 5, 2026MediumNewsSecurityHashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The most serious is CVE-2026-16498 (CVSS score: 10.0), a cross-tenant flaw in Terraform MCP Server's stateless HTTP mode where one user's Terraform token can be reused for later users' requests, because the underlying MCP library does not assign unique session identifiers. Veeam's CVE-2026-58073 (CVSS score: 9.5) lets an unauthenticated attacker impersonate a managed agent and obtain its credentials, though its high attack complexity limits exploitation.
Fix: Update Terraform MCP Server to version 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17.
The Hacker News
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.