Fetching from the wire…
Public story · 2026-02-22 · source-backed
The most comprehensive MCP security analysis published this week. Five risk categories, two named CVEs, and the devastating 53%/8.5% static-credentials-to-OAuth ratio. Required reading for anyone deploying MCP servers. Bitdefender
Each link below shares sources, entities, or timing with this story.
Bitdefender published the most alarming MCP security metric to date: 53% of open-source MCP server implementations rely on insecure static credentials while only 8.5% use OAuth. The report identifies five risk categories: opt-in (not default) security, supply chain poisoning,...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
Astrix analysis of 5,000+ open-source MCP servers: 53% rely on static API keys, only 8.5% implement OAuth. The MCP spec now supports OAuth 2.1 with PKCE and .well-known/oauth-protected-resource discovery. Five risk domains: authentication gaps, supply chain weaponization, priv...
GitHub added allowedMcpServers and deniedMcpServers keys to enterprise Copilot managed settings on August 6, configured to fail closed on malformed config, then followed on August 7 with a usage API exposing totals_by_3rd_party_agent for per-agent spend attribution (digitalapp...
May 2026 produced CVEs for Oracle SQL injection, nginx-ui CVSS 9.8 full takeover, and code-mcp command injection. OX Security documented a systemic RCE flaw across packages with 150M+ downloads. Anthropic has said the behavior is "expected." That's their position. My position:...
The MCP ecosystem now has 30 documented CVEs across six weeks spanning three attack layers: server-side injection (43%), protocol library flaws, and developer tooling vulnerabilities. Simultaneously, the AIUC-1 Consortium reports 80% of enterprises have observed risky agent be...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.