Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
16 articles

#MCP

All CosmicBytez Labs articles tagged #MCP, across news, security advisories, how-to guides, and projects.

  • SecurityAug 22, 2026

    CVE-2026-62316: Microsoft UFO MCP Server DNS Rebinding and SSRF via Missing Host Validation

    CVSS 8.8: Microsoft's UFO framework MCP server binds to localhost but skips Host/Origin header checks, enabling DNS rebinding and SSRF attacks. Fixed in 3.0.8.

  • NewsAug 11, 2026

    Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

    Researchers from the ASSET Research Group disclosed GhostSplice — a novel cross-channel trust fragmentation attack that splits malicious instructions across multiple MCP tool calls, bypassing safety filters to make AI coding agents like Cursor exfiltrate SSH keys, .env files, and source code.

  • SecurityAug 11, 2026

    CVE-2026-19516: SSRF in mcp-grafana Allows Arbitrary Outbound Requests

    A critical server-side request forgery vulnerability in mcp-grafana lets callers hijack the MCP server's outbound HTTP requests via a caller-supplied X-Grafana-URL header, enabling SSRF attacks against internal and external hosts.

  • NewsletterAug 11, 2026

    Weekly Digest — Issue #30

    GhostSplice turns AI coding agents against themselves, DeadLock builds blockchain ransomware infra, and hackers shut a Polish turbine via cellular.

  • NewsAug 10, 2026

    Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    This week's security roundup covers agentic AI containment failures, a critical Metabase zero-day, malicious MCP plugins targeting AI assistants, and persistent router firmware backdoors.

  • NewsJul 30, 2026

    The Network Has Become the Control Plane for AI Security

    As AI agents, copilots, and LLM-powered applications proliferate across enterprise environments, traditional packet-inspection firewalls are blind to the threats they introduce. Check Point argues the network layer — the universal chokepoint for all AI traffic — must evolve into an intent-aware enforcement platform.

  • NewsJul 29, 2026

    Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

    A maximum-severity flaw (CVE-2026-59726, CVSS 10.0) in the Ruflo open-source agent harness for Claude Code and OpenAI Codex allows unauthenticated remote code execution and AI memory poisoning via the MCP protocol.

  • NewsJul 16, 2026

    2-Click Cursor Exploit Enables Dev Environment Takeover

    DeepJack: two clicks in Cursor IDE silently installs a malicious MCP server with full user privileges, stealing source code and secrets. Unpatched in July 2026.

  • SecurityJul 16, 2026

    CVE-2026-46339: 9Router Unauthenticated Plugin Registration & MCP Command Execution

    A critical CVSS 10 vulnerability in 9Router AI router versions 0.4.30–0.4.36 allows unauthenticated attackers to register custom plugins and execute...

  • SecurityJul 3, 2026

    CVE-2026-52830: fast-mcp-telegram Path Traversal Enables Bearer Token Bypass

    A critical path traversal vulnerability in the fast-mcp-telegram Telegram MCP Server allows attackers to bypass Bearer token authentication and read...

  • SecurityMay 17, 2026

    CVE-2026-8719: WordPress AI Engine Plugin Privilege

    A missing WordPress capability check in the AI Engine plugin's MCP OAuth bearer-token path allows any authenticated user to escalate privileges to...

  • SecurityApr 24, 2026

    CVE-2026-6942: radare2-mcp OS Command Injection via Shell

    A critical OS command injection vulnerability in radare2-mcp 1.6.0 and earlier allows remote attackers to execute arbitrary commands by bypassing the...

  • NewsApr 20, 2026

    Anthropic MCP Design Vulnerability Enables RCE, Threatening

    Cybersecurity researchers have discovered a critical by-design weakness in the Model Context Protocol architecture that enables arbitrary command...

  • SecurityMar 17, 2026

    CVE-2025-69902: Critical Command Injection in kubectl-mcp-server

    A critical command injection vulnerability in kubectl-mcp-server allows unauthenticated attackers to execute arbitrary OS commands through unsanitized...

  • ProjectMar 11, 2026

    Claude Code for IT Operations: Building a Multi-Project

    Transform Claude Code from a chatbot into a DevOps co-pilot. Set up CLAUDE.md templates, custom hooks, reusable agents, deployment skills, and MCP server...

  • NewsFeb 17, 2026

    Trojanized MCP Server Deploys StealC Infostealer Targeting

    A SmartLoader campaign distributes a trojanized Model Context Protocol (MCP) server disguised as Oura Health's legitimate tool, deploying StealC...