Fetching from the wire…
Top 5 · 2026-03-03 · source-backed
The MCP ecosystem now has 30 documented CVEs across six weeks spanning three attack layers: server-side injection (43%), protocol library flaws, and developer tooling vulnerabilities. Simultaneously, the AIUC-1 Consortium reports 80% of enterprises have observed risky agent behaviors including unauthorized system access, while only 21% have complete visibility into agent permissions. Cisco responded by shipping four open-source security scanners (MCP scanner, A2A scanner, pickle fuzzer, skill file scanner). OWASP published its Top 10 for Agentic Applications introducing the "Least Agency" principle. The infrastructure is maturing, but the attack surface is expanding faster. DEV Community | Help Net Security | Cisco Blog
Each link below shares sources, entities, or timing with this story.
The 2026 State of AI Security Report from Cisco ships real tools, not just analysis: an MCP scanner, an A2A protocol scanner, a pickle format fuzzer, and a skill file scanner — all open-source. The data behind it: 83% of organizations plan agentic AI deployment but only 29% fe...
Of 53 tracked agentic projects, 28 are coding agents, and the five fastest-growing tools, Claude Code, Gemini CLI, Codex, Cline, and Aider, are all in that category (Help Net Security). Security advisories cluster around n8n (57), Claude Code (22), AutoGPT (15), Dify (13), and...
AAIF will govern MCP, Block's Goose, AGENTS.md, and Google's A2A under vendor-neutral open governance. AWS, Cisco, Google, Microsoft, Salesforce, SAP, and ServiceNow are participating. Both inter-agent communication and tool access protocols now have neutral stewardship. Linux...
Two new attack classes emerged: Anthropic's own official Git MCP server has three CVEs (CVE-2025-68143/44/45) enabling RCE via prompt injection. MCP Watch, a security scanner designed to audit MCP servers, itself contains a command injection (CVE-2025-66401). MCPJam Inspector...
Hudson Rock got hold of the archive and counted it. 433,909 files. 118,829 CI runner dumps traced to 2,488 corporate domains. AWS keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys belonging to NVIDIA, Volkswagen, Micr...
Cisco's second annual report declares MCP and agent communication protocols the dominant AI risk for 2026. The report documents real-world attacks including a malicious MCP package masquerading as a Postmark email integration that BCC'd every email to an attacker-controlled ad...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.