Fetching from the wire…
Security2026-04-21 · source-backed
Adversa AI's roundup shows Golf Scanner (20 checks across 7 IDEs), Astrix MCP Secret Wrapper (runtime vault integration), and mcp-sec-audit all shipped in April. PipeLab's "State of MCP Security 2026" is the first incident-by-incident mapping against the OWASP MCP Top 10. The mcp-remote library (500K+ downloads) had a CVSS 9.6 RCE. No more excuses. Run Golf Scanner on your MCP setup this week.
Each link below shares sources, entities, or timing with this story.
May 2026 produced CVEs for Oracle SQL injection, nginx-ui CVSS 9.8 full takeover, and code-mcp command injection. OX Security documented a systemic RCE flaw across packages with 150M+ downloads. Anthropic has said the behavior is "expected." That's their position. My position:...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
The NSA released authoritative MCP security guidance this month, walking through the protocol's inverted client-server pattern, unverified task propagation between chained servers, and arbitrary-code-execution exposure (Adversa AI). When the NSA ships design guidance for your...
1. Set package cooldown to 72 hours across all your package managers. pnpm: resolution-time=72h, uv: --exclude-newer, npm via .npmrc. This single config change would have protected you from the LiteLLM attack. Willison's survey covers all seven managers. 2. Install Lasso Secur...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.