Fetching from the wire…
Agents2026-06-14 · source-backed
The NSA released authoritative MCP security guidance this month, walking through the protocol's inverted client-server pattern, unverified task propagation between chained servers, and arbitrary-code-execution exposure (Adversa AI). When the NSA ships design guidance for your protocol, it's no longer a hobbyist plumbing layer, it's critical agent infrastructure with a government baseline you can audit against. Pair it with the finding that ~40% of remote MCP servers expose tools with no auth, and Censys counting 12,520 internet-reachable MCP services (PipeLab). Treat MCP endpoints like any other API surface. Internet-facing means attacker-facing.
Each link below shares sources, entities, or timing with this story.
The guidance walks through MCP's inverted client-server pattern, unverified task propagation between servers, and arbitrary-code-execution exposure (Adversa AI). The single highest-impact line: put authentication in front of every remote MCP server and pull unauthenticated one...
Adversa AI's roundup shows Golf Scanner (20 checks across 7 IDEs), Astrix MCP Secret Wrapper (runtime vault integration), and mcp-sec-audit all shipped in April. PipeLab's "State of MCP Security 2026" is the first incident-by-incident mapping against the OWASP MCP Top 10. The...
VIPER-MCP swept roughly 40,000 MCP server repos and produced 106 zero-days and 67 CVEs, while Censys counted 12,520 internet-exposed MCP services with about 40% completely unauthenticated (Adversa AI). Akamai separately disclosed SQL injection in Apache Doris MCP and unauthent...
This one rearranged my week. An essay published August 4 walks through Databricks' independent benchmark of coding harnesses against its own multi-million-line codebase. Pi, a harness with four built-in tools and a system prompt under 1,000 tokens, paired with Opus 4.8 at xhig...
Adversa AI's May 2026 report tested 11 MCP registries and successfully poisoned 9 of them. Attack vectors include unauthenticated UI injection, hardening bypasses in "protected" environments like Flowise, and zero-click prompt injection in Windsurf and Cursor. Anthropic has de...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.