#MCP
15 stories taggedMCP.

A flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins
Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.

One HTTP Request Turns Bifrost AI Gateway Into a Shell
A default-off auth setting in the popular open-source AI gateway lets anyone who can reach it run programs as the server user. The fix ships in 2.1.0.

AIR Security Raises $50 Million to Build a Firewall for AI Agents
A new startup wants to screen the AI tools companies are rushing to adopt, checking them for hidden malicious instructions and overly broad permissions before they cause harm.

Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open
A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands the moment a user opened a booby-trapped file in edit mode.

The Boring Break-Ins: Why This Week's Worst Hacks Were the Simplest
Fresh incidents show attackers rarely need clever tricks. Exposed servers, old bugs and unattended browser sessions did most of the damage this week.

How a Rogue Helper Tool Can Trick an AI Coding Assistant Into Leaking Your Secrets
Researchers show that a hostile plugin can smuggle out SSH keys and source code by breaking one big theft into small, innocent-looking steps.

Weekly Recap: A Metabase Zero-Day, Poisoned AI Plugins, and Routers Left Wide Open
Old bugs are back, supply chains are getting stranger, and the shortest exploit paths keep being the ones nobody guarded.

Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

Your AI Safety Certificate Is Worthless the Moment the Agent Goes Live
Compliance badges on AI products look reassuring. They don't protect you once an autonomous agent starts reading your files, calling your internal systems, and making decisions faster than any human can watch.

A Hidden Comment in Azure DevOps Can Trick an AI Reviewer Into Stealing Code
Microsoft's official Azure DevOps MCP server passes pull request descriptions to AI agents without checking for hidden instructions, letting an outsider steer a reviewer's assistant into private projects.

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing
Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

Poisoned Tool Descriptions Turn Helpful AI Agents Into Quiet Exfiltration Channels
Microsoft Incident Response shows how a single malicious MCP tool description can coax an agent into leaking corporate data without tripping a single policy check.

Amazon Patches CVE-2026-12957 in Q Developer: Malicious Repo Could Drain AWS Credentials via MCP
A workspace-trust prompt was all that stood between a developer and credential theft. Amazon has shipped a fix for the high-severity flaw in its AI coding assistant.

MCP's Enterprise Overhaul Hands Security Problems to Developers
A major revision to the Model Context Protocol repositions itself as enterprise-ready, then quietly offloads the hard security work onto the teams building on top of it.