Fetching from the wire…
Public story · 2026-03-15 · source-backed
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md identity file poisoning as the successor to prompt injection — attackers modify the agent's persistent context rather than injecting into a single prompt. Adversa AI
The roundup ships a CISO playbook including detection engineering rules, incident response checklists, and 40 A2A threat papers synthesized into actionable guidance. Concurrently, CVE-2026-30856 disclosed that Tencent's WeKnora MCP server is vulnerable to tool execution hijacking via ambiguous naming combined with indirect prompt injection. The MCPTox benchmark tested 20 LLM agents against 45 real-world MCP servers (353 tools) and found o1-mini has a 72.8% attack success rate — with more capable models often more susceptible due to better instruction-following of injected payloads. GitLab Security Advisories
Run npx @invariantlabs/mcp-scan today. It auto-discovers MCP configs from Claude Desktop, Cursor, Claude Code, Gemini CLI, and Windsurf, then scans every installed server for prompt injection payloads, tool poisoning, and cross-origin privilege escalation. Invariant Labs This is a sub-minute audit that maps findings to the OWASP MCP Top 10.
Each link below shares sources, entities, or timing with this story.
Sub-minute audit of all MCP servers across Claude Desktop, Cursor, Claude Code, Gemini CLI, and Windsurf. Maps to OWASP MCP Top 10. Invariant Labs
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
Pair this with the espionage story and the picture gets uncomfortable fast. A new arXiv paper (2603.21642) presents the first systematic evaluation of prompt injection through tool-poisoning across seven MCP clients: Claude Desktop, Claude Code, Cursor, Cline, Continue, Gemini...
MIT-licensed desktop app and CLI that auto-detects installed AI clients and manages MCP server configuration for all of them — Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, ChatGPT Desktop, Gemini CLI. Built-in MCP marketplace, team snapshot export, automatic backups...
A multi-stage npm supply chain worm dubbed SANDWORM_MODE deploys rogue MCP servers into configurations of Claude Code, Claude Desktop, Cursor, VS Code Continue, and Windsurf. At least 19 typosquatted packages harvest npm/GitHub tokens, SSH keys, and cloud credentials, then pro...
Triple-stream retrieval (BM25 keyword, vector embeddings, knowledge-graph traversal) fused via Reciprocal Rank Fusion on the iii engine, with SQLite for state and an in-memory vector index, no external database. The economic claim: ~170K tokens/year (~$10) versus ~650K tokens...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.