Agents
MCP Dev Summit Seoul opens Aug 13 as an audit finds 91.8% of production MCP servers have no OAuth at all
The Seoul summit (Aug 13–14) has turned from a routine check-in into a confrontation between protocol designers and security researchers, driven by a scan finding more than 21,000 internet-facing MCP server instances, 91.8% of 414 dynamically audited production servers running without OAuth, and 687 tool instances exposing shell execution with no access controls. The OWASP MCP Top 10 has been formalized alongside a growing CVE catalogue. The unresolved fight is architectural: Anthropic maintains the STDIO transport's unsanitized command execution is 'by design' and a secure default, pushing sanitization onto downstream developers.
Source
↳ Follow the thread