Tag

#MCP

15 stories taggedMCP.

Illustration: a dimly lit developer workstation at night
Identity & Access

A flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins

Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.

4 min read
Illustration: a dark server room rack with a single glowing amber ethernet port emitting soft light
Vulnerabilities

One HTTP Request Turns Bifrost AI Gateway Into a Shell

A default-off auth setting in the popular open-source AI gateway lets anyone who can reach it run programs as the server user. The fix ships in 2.1.0.

4 min read
A network security operations center with multiple analysts monitoring AI agent activities on wraparound displays, permission trees and malicious instruction de
AI Security

AIR Security Raises $50 Million to Build a Firewall for AI Agents

A new startup wants to screen the AI tools companies are rushing to adopt, checking them for hidden malicious instructions and overly broad permissions before they cause harm.

3 min read
Illustration: A developer's workspace with a Jupyter-
Vulnerabilities

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open

A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands the moment a user opened a booby-trapped file in edit mode.

3 min read
A security incident response room with investigators reviewing screens showing exposed database servers, unpatched systems, and abandoned user sessions on publi
Threat Intelligence

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest

Fresh incidents show attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

4 min read
A developer's IDE window displaying code with an active plugin sidebar showing suspicious helper tool options, SSH key references visible in the code editor, am
AI Security

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets

Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

4 min read
A weekly security briefing visualization showing multiple simultaneous threats: Metabase interface with zero-day warning, plugin ecosystem with poison indicator
Threat Intelligence

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open

Old bugs are back, supply chains are getting stranger, and the shortest exploit paths keep being the ones nobody guarded.

4 min read
A security operations center wall of screens showing AI agent activity across enterprise applications, with each screen highlighting different sensitive systems
AI Security

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps

The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

4 min read
Compliance certificate or security badge framed on an office wall becoming faded and irrelevant as a live autonomous agent processes data files in the backgroun
AI Security

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live

Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

4 min read
Illustration: a developer's dual-monitor desk at dusk
AI Security

A Hidden Comment in Azure DevOps Can Trick an AI Reviewer Into Stealing Code

Microsoft's official Azure DevOps MCP server passes pull request descriptions to AI agents without checking for hidden instructions, letting an outsider steer a reviewer's assistant into private projects.

3 min read
Illustration: a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows
AI Security

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About

Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

4 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
Illustration: a darkened modern data center aisle, glowing amber server LEDs reflecting on polished floor
AI Security

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels

Microsoft Incident Response shows how a single malicious MCP tool description can coax an agent into leaking corporate data without tripping a single policy check.

3 min read
Illustration: a developer workstation with a glowing terminal window and an open code editor
Vulnerabilities

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP

A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

3 min read
Illustration: A dense tangle of illuminated fiber-optic cables converging into a glowing central junction node
AI Security

MCP's Enterprise Overhaul Hands Security Problems to Developers

A major revision to the Model Context Protocol repositions itself as enterprise-ready, then quietly offloads the hard security work onto the teams building on top of it.

3 min read
© 2026 Threat Vectr