Fetching from the wire…
Security2026-05-10 · source-backed
Adversa AI's May 2026 report tested 11 MCP registries and successfully poisoned 9 of them. Attack vectors include unauthenticated UI injection, hardening bypasses in "protected" environments like Flowise, and zero-click prompt injection in Windsurf and Cursor. Anthropic has declined to modify the protocol architecture, calling the behavior "expected." Treat MCP marketplace installs like untrusted npm packages. Audit before you install. Pin versions. Monitor egress.
Each link below shares sources, entities, or timing with this story.
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
May 2026 produced CVEs for Oracle SQL injection, nginx-ui CVSS 9.8 full takeover, and code-mcp command injection. OX Security documented a systemic RCE flaw across packages with 150M+ downloads. Anthropic has said the behavior is "expected." That's their position. My position:...
LayerX Security disclosed a CVSS 10/10 zero-click RCE affecting 10,000+ DXT users — a single malicious Google Calendar event achieves full system compromise because DXT MCP servers run with full host privileges and no sandboxing. Critically, Anthropic stated it "falls outside...
The Amazon Q bug is one instance of a 2026 pattern: MCP configuration carried in repositories is now an RCE supply-chain vector, not just untrusted tool output. Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI are all vulnerable to MCP-based auto-launch attacks (Windsurf...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
Six clients. One manifest. Zero vendor lock. Vercel published Agent Plugins 1.0.0 on August 6, an openly licensed spec that bundles Agent Skills and MCP servers behind a single portable manifest. The shape is deliberately boring: a plugin.json requiring only schemaVersion and...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.