AgentsCVE-2026-27896 MCP Go SDK Case-Insensitive Security BypassCVE Reports·high signalXBlueskyLinkedInCopy linkHigh-severity interpretation conflict in official MCP Go SDK. Go encoding/json case-insensitive matching lets attackers bypass WAFs. Fixed in v1.3.1.SourceSource pageCVE Reports↳ Follow the threadStack layer / Threat patternClaude Code 2.1.238 adds headersHelper for plugin marketplaces and strips inherited credentials from MCP helper commandsClaude Code changelogStack layer / Threat patternCOPA Treats Prompt-Injection Defense as Lifelong Learning, Cutting Attack Success Up to 6.3xarXiv 2608.19982Stack layer / Threat patternNVIDIA Shipped an NVIDIA-Hosted CUDA MCP Server Under Nsight AI for Kernel Writing and Profile AnalysisNVIDIA Developer (surfaced via r/LocalLLaMA)Stack layer / Threat patternSplunk Patches a CVSS 9.1 Deserialization RCE in Its MCP Server AppGBHackersStack layer / Threat patternSalesforce ships Headless 360 MCP Server and takes the Slackbot MCP Client to GASalesforcePolicy dependency / Stack layerPolicyGuide Compiles Policy Into a Workflow Graph and Lifts tau^2-bench Pass^4 From 0.42 to 0.62arXiv 2608.19861Stack layer / Threat patternFortinet Buys Virtue AI to Add Runtime Protection for Agents and MCP ToolsFortinetPolicy dependency / Stack layerLet the model pick NoThink, Short, or Long at response start and cut mean tokens 41% for a 1.4 point accuracy lossarXiv 2608.20256