Fetching from the wire…
Public story · 2026-02-23 · source-backed
Astrix analysis of 5,000+ open-source MCP servers: 53% rely on static API keys, only 8.5% implement OAuth. The MCP spec now supports OAuth 2.1 with PKCE and .well-known/oauth-protected-resource discovery. Five risk domains: authentication gaps, supply chain weaponization, privilege escalation via unscoped tokens, confused deputy attacks, and data exfiltration via trusted channels.
Builder action: Implement OAuth 2.1 with PKCE for all production MCP servers. Use short-lived tokens (5-30 min). Static API keys in MCP servers are the equivalent of storing passwords in plaintext. The tooling exists — adoption is the bottleneck.
Source: Bitdefender | Astrix
Each link below shares sources, entities, or timing with this story.
Bitdefender published the most alarming MCP security metric to date: 53% of open-source MCP server implementations rely on insecure static credentials while only 8.5% use OAuth. The report identifies five risk categories: opt-in (not default) security, supply chain poisoning,...
The SANDWORM_MODE npm worm introduces a brand-new attack class: malicious MCP server injection via supply chain compromise. At least 19 typosquatted packages modify MCP configurations of Claude Code, Cursor, Windsurf, and VS Code Continue, installing rogue MCP servers that har...
The first real supply chain attack on the agent instruction layer landed this week, and it's worse than the early reports suggested. A campaign dubbed ClawHavoc planted 1,184 malicious skills in ClawHub — OpenClaw's official skill marketplace — by embedding adversarial instruc...
19. Cisco Blog — AI Security 2026 20. Cybersecurity Dive — MCP 21. Bitdefender — MCP Security 22. Adversa AI — MCP TOP 25 23. Vulnerable MCP Project 24. SiliconANGLE — Cogent Security 25. NIST AI Agent Standards
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
The new authorization spec, co-developed by Anthropic, Arcade, Microsoft, and Okta/Auth0, classifies MCP servers as OAuth 2.1 resource servers and standardizes audience binding via Resource Indicators (RFC 8707) and token exchange via RFC 8693. Aembit's writeup explains the ch...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.