Model Context Protocol
The Model Context Protocol and the servers and clients that expose tools and data to models through it.
- All items
- 295
- Last 90 days
- 133
- Change
- +53%vs 87 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 2 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 7 |
| Sep 2025 | 3 |
| Oct 2025 | 3 |
| Nov 2025 | 2 |
| Dec 2025 | 4 |
| Jan 2026 | 4 |
| Feb 2026 | 12 |
| Mar 2026 | 22 |
| Apr 2026 | 27 |
| May 2026 | 31 |
| Jun 2026 | 25 |
| Jul 2026 | 43 |
| Aug 2026 | 45 |
| Sep 2026 | 40 |
| Oct 2026 | 16 |
91 items
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Apr 20, 2026MediumNewsSecurityIndustryOX Security researchers reported a design weakness in Anthropic's Model Context Protocol (MCP) that enables arbitrary command execution on any system running a vulnerable MCP implementation, exposing user data, internal databases, API keys and chat histories. The flaw sits in unsafe defaults in how MCP configuration works over the STDIO transport, and it is present in Anthropic's official SDK across Python, TypeScript, Java and Rust, affecting more than 7,000 publicly accessible servers and software packages with over 150 million downloads. Anthropic declined to modify the protocol's architecture, and some vendors have issued patches while the reference implementation remains unaddressed.
Fix: To counter the threat, it's advised to block public IP access to sensitive services, monitor MCP tool invocations, run MCP-enabled services in a sandbox, treat external MCP configuration input as untrusted, and only install MCP servers from verified sources.
The Hacker NewsRCE by design: MCP architectural choice haunts AI agent ecosystem
Apr 16, 2026MediumNewsSecuritySafetyOX Security researchers report that the STDIO transport in Anthropic's MCP reference implementation lets client applications pass arbitrary commands to StdioServerParameters, which execute with the parent process's permissions, exposing systems to remote code execution. Anthropic, LangChain and FastMCP maintain this is by design and that client developers must sanitize MCP configurations. The researchers say they executed commands on six official services and took over thousands of public servers across more than 200 open-source GitHub projects.
CSO OnlineCodex for (almost) everything
Apr 16, 2026InfoNewsIndustryOpenAI released a major update to Codex, its coding agent used by more than 3 million developers weekly. The update adds background computer use, where multiple agents can operate Mac apps in parallel by seeing, clicking and typing with their own cursor, plus an in-app browser, image generation with gpt-image-1.5, memory of user preferences, and more than 90 plugins that combine skills, app integrations and MCP servers.
OpenAI BlogCritical Nginx UI auth bypass flaw now actively exploited in the wild
Apr 15, 2026MediumNewsSecurityA critical flaw in Nginx UI, a web-based management interface for Nginx with Model Context Protocol (MCP) support, is being actively exploited. Tracked as CVE-2026-33032, it stems from the unprotected '/mcp_message' endpoint, letting remote attackers invoke MCP tools, including config file writes and nginx reloads, without credentials. Pluto Security's scans found 2,600 publicly exposed instances potentially vulnerable.
Fix: NGNIX released a fix in version 2.3.4, and the latest secure version of nginx-ui is 2.3.6.
BleepingComputerCritical nginx UI tool vulnerability opens web servers to full compromise
Apr 15, 2026MediumNewsSecurityIndustryPluto Security published details of CVE-2026-33032, a critical flaw in the open-source nginx UI configuration tool, with a CVSS score of 9.8. The flaw sits in the MCP server support added in late 2025, where the /mcp_message endpoint lacks authentication, exposing 12 MCP tools that include config writes with automatic nginx reload. The flaw has been under active exploitation since March, and Pluto Security found 2,689 internet-reachable vulnerable instances using Shodan.
Fix: Apply the recommended fix, version 2.3.4, released March 15. For those who cannot patch immediately, disable MCP or lock the IP whitelist to trusted hosts, and review access logs for unusual configuration changes.
CSO Online‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks
Apr 15, 2026MediumNewsSecurityIndustryResearchers warn that a flaw in Anthropic's Model Context Protocol lets unsanitized commands execute silently. The flaw could enable full system compromise across widely used AI environments.
SecurityWeekSecure AI agent access patterns to AWS resources using Model Context Protocol
Apr 14, 2026InfoNewsSecurityIndustryThis AWS blog post explains how to secure AI agents and coding assistants that access AWS resources through the Model Context Protocol (MCP). It argues that agents can do anything their granted entitlements allow, so IAM permissions must be designed as deterministic controls, and it presents three IAM security principles with policy examples.
AWS Security Blog6 ways attackers abuse AI services to hack your business
Apr 6, 2026MediumNewsSecurityIndustryAttackers are abusing AI services that enterprises rely on, a trend experts describe as living off the AI land. One example is a counterfeit MCP server package impersonating Postmark, which ran silently for 15 versions and siphoned sensitive email until detected, and was downloaded 1,500 times per week from the node.js package registry. Other examples include the SesameOp backdoor hiding command traffic in the OpenAI Assistants API and researchers showing Microsoft Copilot and Grok could be manipulated to fetch attacker-controlled URLs.
CSO OnlineTools, um MCP-Server abzusichern
Apr 2, 2026InfoNewsSecurityIndustryA German B2B article on MCP security says the Model Context Protocol connects AI agents to data sources and is gaining popularity in enterprises, though vulnerabilities were found at Asana and Atlassian. It notes progress such as OAuth support and an official MCP Registry, while ongoing risks include prompt injection, tool poisoning and token theft. The piece then outlines what MCP security tools should offer, starting with MCP server discovery.
CSO OnlineAI can push your Stream Deck buttons for you
Apr 1, 2026InfoNewsIndustryElgato's Stream Deck 7.4 software update adds Model Context Protocol (MCP) support. This lets AI assistants such as Claude, ChatGPT, and Nvidia G-Assist find and activate Stream Deck actions for users, who can type or speak requests. Users still configure actions in the Stream Deck app as before.
The Verge (AI)AI Conundrum: Why MCP Security Can't Be Patched Away
Mar 19, 2026LowNewsSecurityResearchA researcher speaking at the RSAC 2026 Conference argues that MCP introduces security risks into LLM environments. According to the source, these risks are architectural rather than easily fixable.
Dark ReadingNavigating Security Tradeoffs of AI Agents
Mar 18, 2026LowNewsSecurityIndustryPalo Alto Networks' Unit 42 argues that AI agent security is a tradeoff between safety and productivity, and that agent risk comes from the privileges granted to them. The authors predict intrusions will follow two pathways: attacks on the open-source AI ecosystem, and attacks on an organization's internal AI agents. They describe model file attacks, where malicious model files hide executable code, and rug pull attacks, where a compromised MCP server is modified to act maliciously after an LLM integrates with it.
Fix: Teams must scan model files with tools that can parse machine learning formats, and load models in isolated containers, virtual machines or browser sandboxes. Organizations should prefer remote MCP servers whose code is maintained by trusted organizations, which reduces but does not eliminate the risk of rug pull attacks.
Palo Alto Unit 42AI Agents: The Next Wave Identity Dark Matter - Powerful, Invisible, and Unmanaged
Mar 3, 2026LowNewsSecurityIndustryAn article argues that AI agents built on the Model Context Protocol (MCP) are spreading through enterprises faster than governance controls, and that these non-human identities sit outside traditional IAM as "identity dark matter." It cites a Team8 2025 CISO Village Survey finding that nearly 70% of enterprises already run AI agents in production.
The Hacker NewsThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories
Feb 26, 2026LowNewsSecurityIndustryThis ThreatsDay bulletin covers several stories, including Kali Linux adding an integration with Anthropic's Claude through the Model Context Protocol (MCP) to turn natural language into technical commands. It also reports Belarus-linked Android spyware ResidentBat, used by Belarusian authorities for surveillance, and CrowdStrike's finding that the average e-crime breakout time dropped to 29 minutes in 2025, a 65% increase in speed from 2024.
The Hacker NewsFigma partners with OpenAI to bake in support for Codex
Feb 26, 2026InfoNewsIndustryFigma is integrating OpenAI's coding tool Codex so users can create and tweak designs from within their coding environments. The integration lets users move between Figma and Codex through Figma's MCP (Model Context Protocol) server, and it follows a similar Figma partnership with Anthropic for Claude Code a week earlier. OpenAI said over a million users use Codex weekly.
TechCrunchClaude Code Flaws Allow Remote Code Execution and API Key Exfiltration
Feb 25, 2026MediumNewsSecurityIndustryCheck Point Research disclosed multiple flaws in Anthropic's Claude Code that let a malicious repository run arbitrary shell commands and exfiltrate Anthropic API keys when a user opens it. The flaws span hooks, MCP server configuration and environment variables, and CVE-2026-21852 involves a settings file that redirects API requests via ANTHROPIC_BASE_URL before the trust prompt appears.
Fix: Fixed in version 1.0.87 (September 2025) for the untrusted project hooks issue, fixed in version 1.0.111 (October 2025) for CVE-2025-59536, and fixed in version 2.0.65 (January 2026) for CVE-2026-21852.
The Hacker NewsNew Relic launches new AI agent platform and OpenTelemetry tools
Feb 24, 2026InfoNewsIndustryNew Relic launched the New Relic Agentic Platform, a no-code system for building and managing data observability AI agents that monitor company data for bugs and issues. The platform supports the model context protocol (MCP) and integrates with other New Relic tools. The company also added OpenTelemetry capabilities to its application performance monitoring (APM) agents, letting enterprises manage OTel data streams alongside other data sources.
TechCrunchShai-Hulud-style NPM worm hits CI pipelines and AI coding tools
Feb 24, 2026MediumNewsSecurityIndustrySocket researchers uncovered an active npm supply chain campaign they named SANDWORM_MODE, a Shai-Hulud-style worm that spreads through at least 19 typosquatted packages impersonating developer utilities and AI tools, including three that impersonate Claude Code and one that targets OpenClaw. The malware harvests npm and GitHub tokens, environment secrets and cloud keys, then uses them to push malicious changes into other repositories. It also deploys a malicious MCP server into AI assistant configurations, where prompt injection can trick the assistant into sending local SSH keys or cloud credentials to the attacker.
Fix: The source states that npm has hardened the registry against Shai-Hulud-class worms, with short-lived, scoped tokens, mandatory two-factor authentication for publishing, and identity-bound "trusted publishing" from CI. It says these controls are designed to contain the blast radius from stolen secrets, but their effectiveness depends on how quickly maintainers adopt them.
CSO OnlineThe rise of the evasive adversary
Feb 24, 2026LowNewsSecurityIndustryCrowdStrike's 12th annual Global Threat Report finds that AI-enabled adversary attacks rose 89% year over year, with threat actors using generative tools to refine phishing lures, generate malware scripts, and accelerate reconnaissance. Malware-free techniques accounted for 82% of detections in 2025, up from 51% in 2020. The report also describes a malicious MCP server, postmark-mcp, that impersonated a Postmark-maintained server and bcc'd an adversary on every email sent.
CSO OnlineSmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
Feb 17, 2026MediumNewsSecurityIndustryStraiker's AI Research (STAR) Labs reports a SmartLoader campaign that distributes a trojanized version of the Oura MCP server, which connects AI assistants to Oura Ring health data. The threat actors built fake GitHub forks and contributor accounts to manufacture credibility, then submitted the malicious server to the MCP Market registry, where it remains listed. Launching it via a ZIP archive runs an obfuscated Lua script that drops SmartLoader, which deploys the StealC infostealer to steal credentials, browser passwords and cryptocurrency wallet data.
Fix: As mitigations to combat the threat, organizations are recommended to inventory installed MCP servers, establish a formal security review before installation, verify the origin of MCP servers, and monitor for suspicious egress traffic and persistence mechanisms.
The Hacker News
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.