NewsMCP Breach Timeline Nine Confirmed Breaches Three CVEsAuthZed·high signalXBlueskyLinkedInCopy linkAuthZed documents nine confirmed MCP breaches in 2025 including CVE-2025-49596, CVE-2025-6514, CVE-2025-53967. Every major integration point breached.SourceSource pageAuthZed↳ Follow the threadShared entity / Threat patternPraisonAI Validated MCP Origins With startswith, So localhost.attacker.com Passed the AllowlistGitHub Security AdvisoriesShared entity / Stack layerHKUDS/nanobot Reached 47,419 Stars and 8,369 Forks in Under Seven Months but Has Not Tagged a Release Since July 25GitHubShared entity / Stack layerProduct Hunt, August 25: akta.pro Wins at 408 Votes Selling Private-Company Data Priced Per Section So Agents Only Pay for Fields They Ask ForProduct HuntPolicy dependency / Stack layerMCP-Universe RL trains tool-use agents by using MCP servers as the RL environment interfacearXivStack layer / Threat patternCROSS-CATEGORY: The Guardrail Layer Around Coding Agents Shipped at Four Different Points in the Lifecycle in 48 HoursHacker News Show HN and Product Hunt (2026-08-24 and 2026-08-25)Policy dependency / Threat patternmcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)GitHub Security AdvisoriesStack layer / ContrastCyberFactory Turns CVEs From the Wild Into Executable Training Tasks; Aegis Hits 52.4% Pass@1 on CyberGym, +22.8 Over Its BasearXiv 2608.23181Stack layer / Threat patternTrustShiftProbe: a compromised MCP server that behaves for N calls then defects hits 69.5% attack success, and the best defense only halves itarXiv