Fetching from the wire…
Skills2026-03-15 · source-backed
Sub-minute audit of all MCP servers across Claude Desktop, Cursor, Claude Code, Gemini CLI, and Windsurf. Maps to OWASP MCP Top 10. Invariant Labs
Each link below shares sources, entities, or timing with this story.
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
MIT-licensed desktop app and CLI that auto-detects installed AI clients and manages MCP server configuration for all of them — Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, ChatGPT Desktop, Gemini CLI. Built-in MCP marketplace, team snapshot export, automatic backups...
Socket.dev disclosed a self-replicating npm worm with a McpInject module that creates fake MCP servers targeting Claude Code, Cursor, Windsurf, VS Code Continue, and Claude Desktop. At least 19 typosquatted packages were compromised. This is purpose-built malware targeting the...
Pair this with the espionage story and the picture gets uncomfortable fast. A new arXiv paper (2603.21642) presents the first systematic evaluation of prompt injection through tool-poisoning across seven MCP clients: Claude Desktop, Claude Code, Cursor, Cline, Continue, Gemini...
A multi-stage npm supply chain worm dubbed SANDWORM_MODE deploys rogue MCP servers into configurations of Claude Code, Claude Desktop, Cursor, VS Code Continue, and Windsurf. At least 19 typosquatted packages harvest npm/GitHub tokens, SSH keys, and cloud credentials, then pro...
Pomeroy v1, posted to Show HN September 8, is a menu-bar app that holds the system permissions and serves nine native apps (Mail, Calendar, Reminders, Notes, Contacts, iMessage, Maps, Shortcuts, Weather) over MCP to 20+ clients including Claude Desktop, Claude Code, Cursor, VS...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.