Fetching from the wire…
Top 5 · 2026-03-01 · source-backed
LayerX Security disclosed a CVSS 10/10 zero-click RCE affecting 10,000+ DXT users — a single malicious Google Calendar event achieves full system compromise because DXT MCP servers run with full host privileges and no sandboxing. Critically, Anthropic stated it "falls outside our current threat model." This creates a new risk category: when upstream vendors explicitly decline to patch critical vulnerabilities, builders must implement their own trust boundaries. What to do: Audit which DXT extensions have executor access. Treat any MCP connector processing external data as a potential injection vector.
Each link below shares sources, entities, or timing with this story.
LayerX disclosed that DXT extensions run unsandboxed with full system privileges. An attacker can craft a malicious calendar event that chains a low-risk connector to a high-risk local executor — achieving full RCE without any user click. Anthropic reportedly declined to fix,...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
May 2026 produced CVEs for Oracle SQL injection, nginx-ui CVSS 9.8 full takeover, and code-mcp command injection. OX Security documented a systemic RCE flaw across packages with 150M+ downloads. Anthropic has said the behavior is "expected." That's their position. My position:...
Adversa AI's May 2026 report tested 11 MCP registries and successfully poisoned 9 of them. Attack vectors include unauthenticated UI injection, hardening bypasses in "protected" environments like Flowise, and zero-click prompt injection in Windsurf and Cursor. Anthropic has de...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.