Critical Bifrost AI Gateway Flaw Let Attackers Run Commands Without Credentials
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Signal
21 articles covering "MCP"
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.
Cloudflare opens a private beta of WriteGuard, a policy and audit layer that classifies and can block risky write actions AI agents take through MCP servers.
AMD's open-source local AI agent framework for Ryzen AI NPUs gains a terminal-native agent hub, cross-surface confirmation gates, and MCP security fixes.
A critical Jinja2 template-injection bug let attacker-controlled repository files execute code in the Serena coding agent, bypassing its own trust gate.
Six companies agreed on a shared packaging format for AI agent skills and MCP servers; Anthropic, which created the underlying protocols, is not part of the effort.
GitHub shipped enterprise-wide allow/deny lists for MCP servers reachable through Copilot, enforced with fail-closed policy across the Copilot app, CLI, and VS Code.
The 2026-07-28 MCP release candidate makes the protocol core stateless, formalizes an Extensions framework, and deprecates Roots, Sampling, and Logging. The RC locked May 21 for a July 28 final.
Red Hat used its May 12 Summit keynote to take Red Hat Desktop with Podman Desktop and isolated AI agent sandboxing to general availability, and to preview Red Hat AI 3.4 with vLLM speculative decoding, Model-as-a-Service, MCP tooling, and an agent evaluation hub.
Roblox unveiled an agentic upgrade to its Studio Assistant on April 16, adding a Planning Mode, natural-language Mesh Generation, code-driven Procedural Models, and a playtesting agent that reads logs and uses inputs to find bugs.
At TrailblazerDX 2026, Salesforce unveiled Headless 360, exposing its full platform as APIs, MCP tools, and CLI commands so AI coding agents can build and operate on Salesforce without a browser.
A missing authentication check on a Model Context Protocol endpoint in nginx-ui exposes roughly 2,600 servers to full takeover, and unauthenticated exploitation is practical when paired with a second flaw that leaks a required node secret.