Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
91 items
New Enterprise-Ready MCP Specification Brings New Security Challenges
Jun 26, 2026LowNewsSecurityIndustryThe Model Context Protocol (MCP) moves to version MCP 2026-07-28 on July 28, 2026, with a 12-month deprecation window for legacy versions. Akamai's analysis says the protocol removes several vulnerability classes but adds new attack surfaces, such as predictable state identifiers, MCP-specific HTTP headers that can leak secrets, MCP Apps that bring stored XSS risk, and long-running tasks that enable denial of service.
SecurityWeekAI Threat Readiness Pillar 4: Detect and contain threats in real-time
Jun 23, 2026InfoNewsSecurityIndustryWiz has published Pillar 4 of its AI Threat Readiness series, which covers detecting and containing threats in real time. The article argues that traditional alert-review-investigate workflows cannot keep pace as attack windows shrink to minutes, and that AI workloads such as agents, MCP servers, tools, models, and cloud AI services like Amazon Bedrock, Azure AI, and Vertex AI require new context, telemetry, and monitoring.
Wiz Research BlogMicrosoft fixes AutoGen Studio flaw that enabled code execution
Jun 22, 2026MediumNewsSecurityMicrosoft fixed AutoJack, a vulnerability chain in AutoGen Studio, Microsoft's graphical interface for its open-source multi-agent AI framework. Three weaknesses (localhost-trusting MCP WebSocket, missing authentication on the MCP WebSocket endpoint, and an unvalidated base64-encoded server_params value passed to process launching) let a malicious webpage visited by a developer's browsing agent run arbitrary commands with the developer's account privileges. Microsoft says the code never shipped in a PyPI release, so only developers who built AutoGen Studio from the main GitHub branch during a limited window were exposed.
Fix: Fixed by the hardening commit b047730. The latest PyPI package, autogenstudio 0.4.2.2, does not contain the AutoJack weaknesses. Microsoft recommends deploying AutoGen Studio strictly as a developer prototype in an isolated environment not exposed to the internet, and running it under a low-privilege account in a sandboxed user profile or container.
BleepingComputerMicrosoft says web-enabled AI agents can trigger host-level RCE
Jun 19, 2026MediumNewsSecurityIndustryMicrosoft disclosed AutoJack, a technique in which a malicious webpage rendered by a browsing AI agent reaches a local Model Context Protocol (MCP) service in AutoGen Studio and runs arbitrary processes on the host. The attack chains three weaknesses in AutoGen Studio's MCP WebSocket implementation: an origin allowlist that a local browsing agent can satisfy, authentication that skipped MCP WebSocket paths, and a "server_params" URL value passed to process spawning without an executable allowlist. Microsoft says the vulnerable code existed only in development builds and was never shipped in the current PyPI release, and that the problem could affect a broader class of agentic frameworks.
Fix: For those installing AutoGen Studio from source, the maintainers removed URL-based parameter injection, routed MCP paths through normal authentication flows, and implemented server-side parameter handling keyed to session identifiers.
CSO OnlineNew Platform Uses Cryptographic Invisibility to Protect AI-Built Applications
Jun 9, 2026InfoNewsSecurityIndustryAtsign has launched AI Architect, a product that adds security to AI-assisted coding by having developers specify an app's purpose and generating precise prompts that direct coding agents to produce secure, relevant code. It is delivered as a custom MCP server called AAIA, which gives each resource a unique cryptographic identity with policies controlling its privileges. The source claims that AI-built apps are otherwise likely to contain unknown vulnerabilities.
SecurityWeekMicrosoft identifies seven new ways AI agents can be hacked
Jun 5, 2026InfoNewsSecurityResearchMicrosoft has identified seven new failure modes in agentic AI systems, extending the first Taxonomy of Failure Modes in Agentic AI Systems it published last year. The new modes include Goal Hijacking, Inter-Agent Trust Escalation, Computer Use Agent (CUA) Visual Attack, and MCP / Plugin Abuse. Microsoft attributes the expanding list to rapid mainstream adoption, the maturing Model Context Protocol (MCP) ecosystem, the rise of computer-use agents, and more empirical findings from real-world research.
Fix: Microsoft advises security teams to inventory their supply chain and generate a software bill of materials (SBOM) for every deployed agent. It also recommends verifying agent identity cryptographically rather than positionally, by issuing attestable credentials at provisioning. Teams should add the seven new failure modes to their red-team coverage matrix and audit the human-in-the-loop user experience as a security control.
CSO OnlineClaude Code has an MCP security problem — and your developers are already using it
Jun 5, 2026MediumNewsSecurityIndustryResearchers at Mitiga Labs published an attack chain in which a malicious npm package's post-install hook rewrites ~/.claude.json, redirecting Claude Code's MCP traffic to attacker-controlled infrastructure and intercepting the OAuth bearer tokens stored there in plaintext. Mitiga reported the issue to Anthropic on April 10, and Anthropic replied on April 12 that it was out of scope; the article states no patch exists as of writing. It also recalls two earlier Claude Code flaws, CVE-2025-59536 and CVE-2026-21852, disclosed by Check Point Research in February 2026 and patched by Anthropic.
CSO OnlineFlowise’s MCP implementation can run ghost commands
Jun 1, 2026MediumNewsSecurityResearchers at Obsidian Security disclosed CVE-2026-40933, a one-click remote code execution flaw in self-hosted Flowise deployments through its implementation of MCP stdio servers. Flowise lets users configure stdio servers with arbitrary commands, which the operating system then runs with the Flowise process's privileges, and a malicious chatflow import can trigger this before any save or run. The flaw is rated 9.9 CVSS, and Flowise Cloud is not affected because stdio MCP is disabled there.
Fix: The only complete mitigation recommended by the researchers is turning off MCP stdio by setting "CUSTOM_MCP_PROTOCOL=sse". For those who cannot do so without obstructing operations, pinning trusted packages where possible and reviewing imported chatflows from untrusted sources might help.
CSO OnlineChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
May 29, 2026MediumNewsSecuritySafetyPermiso Security disclosed ChatGPhish, a technique in which a web page that a user asks ChatGPT to summarize can cause the chatgpt.com response renderer to display attacker-controlled Markdown links, image URLs, fake security alerts and QR codes as live elements in the assistant's UI. The renderer auto-fetches attacker-hosted images, which can leak the victim's IP, User-Agent and Referer. Separately, Adversa AI documented SymJack and TrustFall, which target AI coding agents and can lead to code execution through malicious repositories and MCP servers.
The Hacker NewsDNS-AID will make AI agents easier to discover, says Linux Foundation
May 29, 2026InfoNewsIndustrySecurityThe Linux Foundation is inviting contributions to DNS-AID, a proposed standard that lets AI agents and MCP servers discover, verify and communicate with one another using existing DNS infrastructure. The proposal suggests domain owners publish a well-known address, _index._agents.{domain}, as a starting point for agent discovery. DNS-AID was initially developed at Infoblox, with contributions from Deutsche Telekom and Amazon in the latest internet draft.
CSO OnlineFastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
May 27, 2026MediumNewsSecurityIndustryA single malformed character in the Host header lets an unauthenticated attacker bypass host-validation protections in Starlette, the Python framework underlying FastAPI, tracked as CVE-2026-48710. Starlette rebuilds the request URL by joining the Host header to the path, and a slash, question mark or hash in the Host header shifts where the path begins, so middleware reads a different path than the one routed. Researchers at X41 D-Sec rated the flaw 7.0 (High), while Starlette's maintainer rated it 6.5 (Moderate), and they said downstream applications built on FastAPI, including AI model-serving tools, gateways and MCP servers, can be affected.
Fix: Starlette's maintainer released a patch through an official GitHub security advisory. The source does not specify a fixed version number.
CSO Online‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems
May 27, 2026MediumNewsSecurityIndustryAdversa AI describes SymJack, an attack that uses a malicious repository to turn AI coding agents into delivery mechanisms for supply chain attacks. A malicious symlink, renamed to look innocuous, is used with a cp command to plant a payload in the agent's configuration, registering a malicious MCP server whose startup command runs attacker code as the user on the next restart. Adversa reports the method worked in all five coding agents it tested, including Claude Code, Gemini CLI, Cursor Agent CLI, Grok Build CLI and GitHub's Copilot CLI.
Fix: Anthropic quietly hardened Claude Code, which now resolves symlinks before asking for approval and shows the real destination path in the prompt. The article calls this a good start and suggests other coding agents could implement similar prompts.
SecurityWeek1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials
May 20, 2026InfoNewsSecurityIndustry1Password has partnered with OpenAI to give Codex access to credentials during development without exposing them in prompts, code, repositories, terminals or the model's context window. The integration uses an Environments MCP Server for Codex, which issues just-in-time, task-scoped credentials and injects them into the application process at runtime.
Fix: 1Password has introduced an Environments MCP Server for Codex that keeps secrets out of prompts, code and model context, with user authentication required at the moment of access.
SecurityWeekSweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’
May 13, 2026InfoNewsSecurityIndustrySweet Security has launched Sweet Attack, an agentic AI red teaming product that runs continuous automated attack testing. The agent reasons over a runtime index of each client's own infrastructure, including topology, identity paths and deployed source code, rather than generic models. It also discovers shadow IT and shadow AI components such as MCP servers, and reevaluates attack paths when new components appear.
SecurityWeekWhy Agentic AI Is Security's Next Blind Spot
May 12, 2026InfoNewsSecurityIndustryThe article argues that security teams lack fluency in agentic AI, which is already running in production across many organizations, and that this gap is widening. It describes three agent categories: general-purpose coding agents such as Claude Code and GitHub Copilot, vendor-built agents using the Model Context Protocol (MCP), and custom agents built by individual users. It illustrates MCP risk with a malicious calendar invite whose hidden instructions an agent reads and executes.
The Hacker News1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolution
May 11, 2026MediumNewsSecurityIndustryKnostic researchers found 1,862 MCP servers exposed to the public internet, and in a manual check of 119 instances every one allowed unauthenticated access to internal tool listings. Some exposed production systems had write access to financial databases, social media accounts and CRM platforms. The article also covers EchoLeak (CVE-2025-32711), a zero-click exploit disclosed by Aim Security in June 2025, and CVE-2025-6514 in the mcp-remote package, which JFrog disclosed in July 2025.
CSO OnlineYour CTEM program is probably ignoring MCP. Here’s how to fix it
May 8, 2026LowNewsSecurityIndustryThe article argues that Model Context Protocol (MCP) servers and shadow AI are a blind spot for security programs, and that integrating MCP risks into a Continuous Threat Exposure Management (CTEM) program can help teams surface exposures. It cites a 2025 malicious npm package, postmark-mcp, which shipped a version that BCC'd outgoing emails to an external address and affected around 300 organizations.
CSO OnlineClaude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
May 7, 2026MediumNewsSecurityIndustryMitiga Labs reported that a tailored npm package can redirect Claude Code MCP traffic through an attacker's proxy, exposing OAuth tokens stored in plain text in ~/.claude.json. The attack requires installing the package on a machine where Claude Code is configured with dynamic authorization MCP servers, and the post-install hook persists across token rotation. Mitiga reported the issue to Anthropic on April 10, 2026, and Anthropic replied on April 12, 2026 that it was out of scope.
SecurityWeekMicrosoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report
May 6, 2026InfoNewsIndustrySecurityMicrosoft was named an Overall Leader and Market Leader in KuppingerCole Analysts' 2026 Emerging AI Security Operations Center (SOC) report. The report argues that SOC effectiveness now depends on intelligence-driven automation rather than alert volume. Microsoft cites Automatic attack disruption, a Phishing triage agent, AI powered incident prioritization, and a Playbook generator, along with the Microsoft Sentinel MCP (Model Context Protocol) Server.
Microsoft Security BlogClosing the Security Gap in the Age of Agentic Coding
Apr 21, 2026InfoNewsSecurityIndustryWiz has added Wiz Code plugins and skills, powered by the Wiz MCP server and WizCLI, that bring its security context into AI-native IDEs and coding agents. The tooling scans AI-generated code in real time and lets coding agents apply Green Agent remediation guidance, which can create pull requests. The announcement responds to frontier models such as Anthropic's Claude Mythos Preview, which the source says can autonomously discover and exploit zero-day vulnerabilities.
Fix: The source describes the Wiz Code plugins, skills, Green Agent remediation plans and automated scans at file save, pre-commit and pre-push as the approach; it does not state a patch, fixed version or configuration fix for a specific vulnerability.
Wiz Research Blog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.