Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
91 items
Obsidian Security Raises $85 Million at $1.1 Billion Valuation
Aug 4, 2026InfoNewsIndustrySecurityObsidian Security announced an $85 million Series D round at a $1.1 billion valuation, led by Crescent Cove Advisors with Greylock Partners and Menlo Ventures participating, bringing total funding above $200 million. The company will use the funds to expand into agentic AI security, offering runtime governance over agents such as Claude Code and Cowork and an inventory of connected MCP servers.
SecurityWeekGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
Aug 4, 2026MediumNewsSecurityIndustryPillar Security found an agent-to-agent attack method in Google's Agent Development Kit for Python (google/adk-python) that could expose secrets and enable pull request poisoning. A public-facing low-privileged agent could be manipulated into passing a prompt to a high-privileged maintainer agent, which exposed its tools via the MCP server and allowed remote command execution and extraction of its GitHub token. Google addressed the issue through hardening but did not consider it eligible for a bug bounty, and a later remote code execution flaw in the Antigravity-SDK-based agent's automation features was fixed in late July.
Fix: Google addressed the first issue through hardening and fixed the second weakness in late July. No further mitigation details are given in source.
SecurityWeekBalancing speed and safety: A control framework for AI coding agents
Jul 30, 2026InfoNewsSecurityIndustryThis AWS Security Blog post presents an application security control framework for AI coding agents such as Kiro and Claude Code, which can open many pull requests quickly and reach beyond the IDE through the Model Context Protocol (MCP). The framework has two pillars: author-time controls that shape agent output in the IDE, and build-time controls that verify and gate code before production. It lists risks ordered by severity, starting with prompt and context injection (R001), and uses AWS Kiro and AWS CodePipeline as a running example.
Fix: For R001, treat non-developer input as untrusted, separate the orchestrating agent from the agent exposed to untrusted content, grant the exposed agent only read-only, least-privilege access, require human approval for irreversible actions, and use version-control steering files to prevent silent tampering. For R002, use security requirements in a steering document plus policy-as-code scanning (Checkov, cfn-nag) in the IDE and pipeline. For R003, use branch protection rules requiring PR approval, pre-commit hooks for security checks, and sandboxed agent runs that prevent direct pushes to protected branches.
AWS Security BlogCritical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
Jul 30, 2026MediumNewsSecurityIndustryNoma Security reported CVE-2026-59726, dubbed RufRoot, a critical flaw (CVSS 10.0) in Ruflo versions prior to 3.16.3. An unauthenticated MCP Bridge, exposed by default, accepts tool invocations at its /mcp endpoint, letting attackers run commands, steal LLM API keys, read user conversations and poison AgentDB memory with a single HTTP request. The researchers validated the attack chain against a default Ruflo deployment on AWS EC2.
Fix: Patch addresses attack chain
CSO OnlineRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Jul 29, 2026MediumNewsSecurityIndustryResearchers at Noma Labs disclosed CVE-2026-59726 (CVSS 10.0), dubbed RufRoot, in Ruflo, an open-source agent meta-harness for Claude Code and Codex, affecting all versions before 3.16.3. The default docker-compose.yml binds port 3001 to 0.0.0.0, exposing an unauthenticated MCP bridge that exposes 233 tools, including terminal_execute. A single unauthenticated POST to /mcp allows remote code execution, enabling theft of LLM provider API keys, reading of stored conversations, and poisoning of AgentDB memory.
Fix: Fixed in version 3.16.3. The patch binds the MCP bridge to the loopback interface by default, gates terminal_execute behind server-side executeTool controls, and enables MongoDB authentication. Operators with exposed instances are advised to close firewall ports 3001 and 27017, rotate all LLM API keys, audit the AgentDB pattern store for injected agentdb_pattern-store entries, and check MongoDB for tampering.
The Hacker NewsAdding a custom MCP server to Claude and ChatGPT
Jul 28, 2026InfoNewsIndustrySimon Willison writes a short TIL post on July 29, 2026, about adding a custom MCP server to the Claude and ChatGPT web chat interfaces. He says the setup is possible but takes quite a few steps and is not obvious.
Simon Willison's WeblogThe risk hiding behind exposed MCP servers
Jul 28, 2026MediumNewsSecurityIndustryWiz Research examined MCP servers left reachable from the Internet, often without authentication, and found several run by Fortune 500 companies. These exposed employee PII, internal business records, write and delete operations, and in some cases code execution and cloud credentials. Roughly 1 in 6 cloud environments where MCP was found exposed at least one server.
Wiz Research BlogMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Jul 22, 2026MediumNewsSecurityIndustryA hidden HTML comment in an Azure DevOps pull request description can hijack a reviewer's AI coding agent through Microsoft's official Azure DevOps MCP server. The repo_get_pull_request_by_id tool returns descriptions without the spotlighting guardrail that other tools in the server already apply, which Manifold Security says is the gap. In a proof of concept run on a local build of v2.7.0, the injected instructions led the agent to trigger a pipeline in another project, read a confidential wiki page, and post it back to the PR.
The Hacker NewsFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Jul 20, 2026MediumNewsSecurityIndustryCybersecurity researchers found nearly 7,600 malicious GitHub repositories created by about 6,600 profiles, more than 800 of which pose as AI skills or Model Context Protocol (MCP) servers to deliver SmartLoader malware in a campaign called FakeGit. The campaign then pushes secondary payloads such as StealC, an information stealer. Island's tests found Anthropic Claude Code, Google Gemini and OpenAI ChatGPT susceptible to surfacing these repositories, a technique it calls AgentBaiting.
Fix: To counter the threat, it's advised to build a catalog of reviewed Skills, MCP servers, and agent plugins, evaluate new agent capabilities in a sandboxed environment first before broader rollout, verify both the publisher and the project to ensure credibility.
The Hacker NewsNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Jul 17, 2026MediumNewsSecurityIndustryA Go botnet called NadMesh targets exposed AI services such as ComfyUI, Ollama, n8n, Open WebUI, Langflow and Gradio, and its operator's dashboard claims 3,811 unique AWS keys. XLab, the QiAnXin research group, published a report on the malware and noted that its figures are internally inconsistent. Per the source, the bots mainly harvest cloud keys, Kubernetes service account tokens and config files, with MCP tool calls such as execute_command ranked high in the controller's exploitation priorities.
The Hacker NewsSASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Jul 15, 2026InfoNewsIndustrySecurityThe article argues that traditional SASE, which backhauls traffic to cloud proxies for decryption and inspection, cannot see data interactions in browsers and AI workflows, such as employees pasting intellectual property into public LLMs or agents using model context protocol (MCP) tool calls. It says TLS 1.3, HTTP/3 and certificate pinning cause traditional proxy inspection to fail, forcing teams to write bypass exceptions. The piece proposes enforcing policy at the point of interaction on the device, using the "Perfect Packet" architecture, which evaluates context at the endpoint before routing.
Fix: Enforce policy at the point of interaction on the device (browser and endpoint), inspecting copy, paste and prompt content locally before data leaves the device, and steer traffic to the closest edge infrastructure, invoking cloud inspection only when a session requires additional verification (the "Perfect Packet" architecture).
The Hacker NewsHow Pentera Turns AI Security Workflows into Validation Engines
Jul 14, 2026InfoNewsSecurityIndustryPentera describes how AI security workflows that rely on scanner output, severity scores and other disconnected risk signals cannot tell whether findings form a real attack path. The source argues that security validation, which emulates attacker techniques against production environments to produce evidence of exploitable exposures, should ground these workflows. Pentera introduced an MCP (Model Context Protocol) Server to make its validation data available to MCP-compatible AI assistants.
The Hacker NewsIntroducing OAuth Support for AWS MCP Server
Jul 9, 2026InfoNewsIndustrySecurityAWS has added OAuth sign-in to its AWS MCP Server, letting agents connect using the same credentials used for the AWS Management Console or AWS CLI. The release adds global condition keys for OAuth, token introspection and revocation, dynamic client registration, new AWS CloudTrail elements, and a headless OAuth API, all compatible with existing IAM configuration. The source notes that authorizing an agent grants access on the user's behalf but does not grant additional AWS permissions.
AWS Security BlogCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
Jul 3, 2026MediumNewsSecurityIndustryCato Networks reports two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8) and dubbed DuneSlide, that can lead to remote code execution outside the IDE's sandbox. The first abuses the working_directory parameter, which adds a non-default path to the allow list, letting a prompt injection delivered through an MCP server request make the LLM overwrite the cursorsandbox executable. The second uses symbolic links to bypass out-of-bounds write protections because of a path canonicalization flaw.
Fix: Patches for both were included in Cursor 3.0, released on April 2. Cato reported the flaws to Cursor in February.
SecurityWeekBuild AI Security Agents with Wiz MCP
Jul 2, 2026InfoNewsIndustrySecurityWiz has announced general availability of Wiz MCP, which lets AI assistants, custom agents, and AI-powered applications securely connect to the Wiz platform. The product gives these tools access to Wiz Security Graph context, outputs from Red, Blue, and Green Wiz AI Agents, and verified Wiz AI Skills for workflows such as vulnerability triage and remediation.
Wiz Research BlogSandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
Jul 1, 2026MediumNewsSecuritySafetyCato Networks researchers found two flaws, CVE-2026-50548 and CVE-2026-50549, in the Cursor AI IDE that let prompt injection break out of its command execution sandbox and reach remote code execution. The exploit needs no prior user privileges or specific user interaction. It is triggered when a victim's innocuous prompt ingests an attacker-controlled payload from an untrusted source, such as an MCP server or a web search result.
Fix: Fixed in version 3.0 of the Cursor IDE, released in April.
CSO OnlineMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft research shows attackers can hijack AI agents by poisoning the description of an MCP tool, causing the agent to quietly send company data to an outside server while each step looks routine. The work comes from Microsoft Incident Response and its Defender security research team. Microsoft says the weakness is a trust gap created by connecting outside tools, not a bug in Copilot itself.
Fix: Treat every connected tool as part of your supply chain: keep a list of approved tool publishers, turn off "allow all," and let an agent use only the specific tools it needs. Treat a tool's description like a system prompt and review changes to it like a code change. Put a human in front of risky actions, such as anything that moves money or shares data.
The Hacker NewsSecuring AI agents: When AI tools move from reading to acting
Jun 30, 2026MediumNewsSecurityIndustryMicrosoft Incident Response describes an attack pattern against MCP tools, the fastest growing part of the agentic AI supply chain, in the third post of its AI Application Security series. The pattern is MCP tool poisoning, mapped to OWASP ASI02 (Tool Misuse) and ASI04 (Agentic Supply Chain Vulnerabilities), and it reflects techniques first disclosed by Invariant Labs in April 2025. The post supplies a playbook for detecting, containing and preventing it with Microsoft security controls.
Fix: The source describes a playbook of detection, containment and prevention using Microsoft security controls, but does not state a specific fix, patch, fixed version or configuration change in the excerpt provided.
Microsoft Security BlogAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Jun 26, 2026MediumNewsSecurityIndustryA high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957 (CVSS 8.5), let a malicious repository run commands and steal a developer's cloud credentials. Amazon Q read the MCP configuration file .amazonq/mcp.json from the open workspace and launched the servers it defined, and those processes inherited the developer's full environment, including AWS keys and cloud CLI tokens. Wiz Research found and reported the flaw, and Amazon has patched it.
Fix: Update. CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's bulletin tells customers to move to 1.69.0, which also closes CVE-2026-12958. Patched plugin minimums: VS Code 2.20 or later, JetBrains 4.3 or later, Eclipse 2.7.4 or later, Visual Studio toolkit 1.94.0.0 or later.
The Hacker NewsMCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension
Jun 26, 2026MediumNewsSecurityWiz Research found a high-severity flaw, CVE-2026-12957, in the Amazon Q Developer Extension for Visual Studio Code. Amazon Q loaded MCP server configurations from .amazonq/mcp.json in the workspace without user consent or a workspace trust check. Because spawned processes inherited the user's full environment, opening a malicious repository could lead to arbitrary code execution and cloud credential theft.
Fix: Fixed in language server version 1.65.0. Affected versions are language server versions below 1.65.0.
Wiz Research Blog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.