Model Context Protocol (MCP)

9 items · Defense 3 · Attacks 5 · Markets 1 · all entities

A scan of public MCP configuration files finds one credential in eight hardcoded

Hush Security says it analysed roughly 82,000 publicly accessible Model Context Protocol configuration files and found hardcoded secrets in 12% of credential slots, 55% of them in formats carrying no vendor-recognisable token pattern, 24% both broad-scope and non-expiring, and 243 still readable in earlier Git commits after being removed from the current file. Chief executive Micha Rave is quoted saying “These files are meant to be committed; the secret never should be.”

Self-reported, untestedHush Security (via PR Newswire) ↗ ·

Two chained flaws let unauthenticated callers reach data through Grafana's MCP server

Pillar Security reports that callers could generate locally-formatted session identifiers to invoke MCP tools with no credentials, reaching Grafana data through the server's own service account, and that the grafana_api_request tool let a caller control the destination, method, path and body of outbound requests including internal services. The issue is tracked as CVE-2026-19516 at CVSS 9.1, published August 11, with Grafana shipping v1.1.0 on August 10 adding optional bearer-token authentication. Pillar puts the server at more than 1.9 million cumulative Docker Hub downloads.

Reported by researchersPillar Security ↗ ·

CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog

CVE-2026-59822 lets an unauthenticated attacker send a fabricated Authorization header to LiteLLM's MCP Streamable HTTP endpoint, triggering an OAuth2 passthrough fallback that replaces failed key validation with an empty authorisation object and admits requests to MCP tooling. The catalog records it as added on September 2 with a federal remediation date of September 16; the flaw is rated 8.8 under CVSS 4.0 and 8.2 under CVSS 3.1 and is fixed in LiteLLM 1.84.0.

Metasploit ships public exploit modules for two AI application platforms

Rapid7's August 28 Metasploit release added 16 modules, two of them targeting AI application software: an unauthenticated remote code execution exploit for Langflow versions 1.10.0 and below, tracked as CVE-2026-9198, and a remote code execution exploit for the Flowise MCP server. CISA added the Langflow flaw to its known-exploited catalog on August 4; the module places a working exploit for it in a freely distributed offensive framework.

On the recordRapid7 ↗ ·

Wiz honeypots record attackers exploiting MCP servers and self-hosted AI stacks

Over a 90-day honeypot study across self-hosted AI services, Wiz Threat Research observed three attack patterns against AI infrastructure: exploitation of Model Context Protocol servers, including an authentication bypass in LiteLLM's MCP gateway that accepted any bearer token and a command-injection flaw used to drop cryptominers; blind indirect prompt injection against LangChain, Flowise, OpenWebUI and Node-RED deployments, confirmed through out-of-band DNS callbacks; and AI-native post-exploitation in which attackers read a compromised LiteLLM process's Python module state in memory to steal master keys rather than searching files.

Reported by researchersWiz ↗ ·

Fortinet buys an agentic-AI security vendor and does not disclose the price

Fortinet acquired Virtue AI, whose products cover agentic-system red-teaming across more than 50 sandboxed environments simulating prompt-injection and MCP attacks, discovery and governance of deployed agents, continuous validation across more than 1,000 risk categories, and runtime guardrails. Fortinet said “financial terms of the transaction are not disclosed, and the amount paid by Fortinet as consideration is immaterial to Fortinet's business.” Chairman and CEO Ken Xie: “AI is fundamentally changing enterprise computing, and security must evolve just as quickly.”

On the recordFortinet ↗ ·

A malicious MCP server turns hostile only after an agent's third tool call

Pillar Security reports a GitHub account, zellkernel, opening 23 campaign-related pull requests in 74 minutes on August 10 that point projects at a remote MCP endpoint or a hidden local path. The server behaves normally until a connected client reaches three tool calls, after which its tool and prompt responses change to steer the agent toward SSH keys, AWS credentials, shell history and Kubernetes configuration while concealing the activity from the user.

Reported by researchersPillar Security ↗ ·

HashiCorp patches CVSS 10.0 cross-tenant credential reuse flaw in Terraform MCP Server

HashiCorp advisory HCSEC-2026-23 disclosed three vulnerabilities in terraform-mcp-server, led by CVE-2026-16498, a cross-tenant credential reuse issue in streamable-HTTP stateless transport mode that allows one user's Terraform token to be used for subsequent users' tool calls. Versions 0.2.1 through 1.0.0 are affected and version 1.1.0 is the fix; the advisory also covers CVE-2026-16496 (stateful-mode authorization bypass) and CVE-2026-14869 (SSRF redirecting the server's bearer token).

On the recordHashiCorp ↗ ·

"FakeGit" weaponizes ~7,600 repos against coding agents

Island researchers documented ~7,600 malicious GitHub repositories — 800+ disguised as AI skills or MCP servers — using an "AgentBaiting" technique so that LLM coding agents autonomously discover and execute repos that deliver SmartLoader and StealC.

Reported by researchersThe Hacker News ↗ ·