Tag

#MCP

14 stories taggedMCP.

Full-frame overhead photograph of a developer workstation at night, glowing terminal window on a matte black laptop screen showing generic package installation
Threat Intelligence

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest

A run of fresh incidents shows attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek matte-black padlock resting on a softly glowing computer keyboard, cool blue and teal rim ligh
AI Security

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets

Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a darkened developer workstation at night, dual monitors showing blurred lines of Python source code and a te
Threat Intelligence

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open

Old bugs are back, supply chains are getting stranger, and the shortest exploit paths are once again the ones nobody guarded.

4 min read
Macro photograph of exposed copper circuit board traces glowing faintly orange-red under a harsh directional light source, dark industrial metal surface visible
AI Security

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps

The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

3 min read
AI security system with digital shield
AI Security

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live

Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

4 min read
Photoreal editorial shot of a developer's dual-monitor desk at dusk, one screen showing a generic code review interface with a highlighted pull request panel, f
AI Security

A Hidden Comment in Azure DevOps Can Trick an AI Reviewer Into Stealing Code

Microsoft's official Azure DevOps MCP server passes pull request descriptions to AI agents without checking for hidden instructions, letting an outsider steer a reviewer's assistant into private projects.

4 min read
Full-frame photoreal editorial shot of a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows, a small permission
AI Security

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About

Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
AI Security

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels

Microsoft Incident Response demonstrates how a single malicious MCP-style tool description can coax an agent into leaking corporate data — without tripping a single policy check.

3 min read
Vulnerabilities

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP

A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

2 min read
AI Security

MCP's Enterprise Overhaul Hands Security Problems to Developers

A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.

3 min read
AI Security

Microsoft Expands Its Agentic AI Failure Taxonomy With Seven New Attack Classes

From inter-agent trust escalation to MCP plugin abuse, the updated taxonomy surfaces threat categories that didn't exist — or weren't well-understood — when Microsoft published its first version.

2 min read
AI Security

One Click, Full Shell: Flowise MCP Flaw Scores 9.9 CVSS

A sandboxing failure in Flowise's MCP stdio implementation lets an attacker execute arbitrary OS commands with process-level privileges — and the patches so far don't close the hole.

2 min read
AI Security

The Linux Foundation Wants DNS to Be the Phone Book for AI Agents

DNS-AID proposes using existing DNS infrastructure for agent discovery — no new directories, no vendor lock-in, no new protocols to trust.

2 min read
© 2026 Threat Vectr