Fetching from the wire…
Security2026-08-02 · source-backed
Noma Labs disclosed that Ruflo's built-in MCP Bridge exposed 233 tools: including terminal_execute: over an unauthenticated HTTP endpoint on port 3001, bound to 0.0.0.0 by default in the shipped docker-compose. One POST to /mcp gets you shell inside the container, then provider API keys, conversation history, and the ability to poison AgentDB learning-store patterns. A command blocklist existed but applied only to the autopilot flow, not the /mcp endpoint. Disclosed June 30, patched in 3.16.3 within 24 hours. Go check what your agent harness binds to.
Each link below shares sources, entities, or timing with this story.
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
Ten days from spec to shipped client. That's fast even for this ecosystem. The MCP 2026-07-28 revision replaced the bidirectional stateful protocol with request/response. Every request now independently carries protocol version, client identity and capabilities. Cloudflare's t...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
The defense-first MCP pattern from Christian Schneider treats every tool schema like a request from a stranger. A control point outside the client runs a five-stage validation pipeline. Stages 01 through 04 gate the discovery path, inspecting every schema before the model ever...
1. Set package cooldown to 72 hours across all your package managers. pnpm: resolution-time=72h, uv: --exclude-newer, npm via .npmrc. This single config change would have protected you from the LiteLLM attack. Willison's survey covers all seven managers. 2. Install Lasso Secur...
CrowdStrike analyzed 30,000+ AI-generated code skills and found over 25% contained at least one exploitable vulnerability. Claude Opus 4.5 Thinking — the model many teams trust for security-sensitive work — produces correct *and* secure code only 56% of the time at baseline. T...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.