AgentsCoSAI MCP Security White Paper: 12 Threat CategoriesCoSAI·high signalXBlueskyLinkedInCopy linkFirst comprehensive MCP security taxonomy with 40 attack vectorsSourceSource pageCoSAI↳ Follow the threadStack layer / Threat patternThe author of Laya says TypeSafe's Jev is his March 2025 architecture relaunched as a breakthrough, and publishes latency numbers to back itLaya / ConvAI Innovations (Nandakishor Mukkunnoth)Policy dependency / Stack layerICML position paper: every agent framework has reimplemented an operating system badly, so build the OS layerarXivStack layer / Threat patternCVE-2026-93982: OpenPanel writes MCP auth tokens from URL query strings into plaintext logsNVDStack layer / Threat patternJames Mickens argues chain-of-thought monitoring can never be a sound security controlarXivStack layer / Threat patternAn AI agent found the libheif RCE behind Next.js image optimization, and Vercel published the full disclosure timelineVercel BlogStack layer / Threat patternWSO2 Ships Agent Manager GA With MCP Governance and a Kubernetes Sandboxed RuntimeInfoQPolicy dependency / Threat patternCROSS-CATEGORY: Three Spend and Accounting Platforms in 72 Hours Moved From Recording Money to Executing Finance WorkSynthesis of Portal ERP on Bujeti (2026-09-18), PR Newswire on Findity (2026-09-17) and mercury.com/blog (2026-09-16)Stack layer / Threat patternA Model Can Fingerprint vLLM or SGLang From Its Own Output Tokens, Then Exploit ItarXiv 2609.20614