AgentsBitdefender MCP Security — 53% Static Credentials, 8.5% OAuthBitdefender·high signalXBlueskyLinkedInCopy linkFive key MCP risk categories. CVE-2025-6514 CVSS 9.6 RCE, CVE-2025-32711 EchoLeak. 53% open-source MCP servers use insecure static credentials, only 8.5% use OAuth.SourceSource pageBitdefender↳ Follow the threadPolicy dependency / Stack layerSenate Negotiators Weigh a 'Duty of Care' Law Letting Federal Courts Block Unsafe Model Releases and Preempting State AI LawsReutersStack layer / Threat patternClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Stack layer / Threat patternTrueFoundry open-sources TrueForge, an MIT-licensed agent harness pitched against Claude Managed AgentsTrueFoundryStack layer / Threat patternOne operator ran hundreds of Codex- and DeepSeek-driven agents to compromise 440+ PaperCut servers at 395 organizations in 48 countriesGreyNoiseStack layer / Threat patternSalesforce frames its agent stack as an 'Enterprise AI Harness' with a separate AI Control PlaneSalesforcePolicy dependency / Threat patternAnthropic's September threat report: Chinese students produced "more than a dozen possible zero day findings in a single month" with ClaudeAnthropicStack layer / Threat patternCline Ships a Desktop App for Open-Weight Models and Sells Ten of Them From Six Labs for $9.99 FlatCline (corroborated by the Product Hunt leaderboard for 2026-09-11, the GitHub API and newreleases.io for desktop-v0.0.25)Threat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker News