GitGuardian MCP Governance Framework for Enterprise AI
GitGuardian publishes a practical MCP governance framework covering authentication standards, scope control, secrets lifecycle, and credential exposure detection for multi-agent deployments.
High-signal AI/security/automation notes.
GitGuardian publishes a practical MCP governance framework covering authentication standards, scope control, secrets lifecycle, and credential exposure detection for multi-agent deployments.
Three independent scans in June 2026 show ~40% of remote MCP servers run without authentication, while Trend Micro found CVSS 9.8 command-injection flaws in unofficial cloud MCP implementations.
An independent assessment of 100 production AI agents finds only 11% pass basic security, with coding and computer-use agents carrying the highest risk.
Claroty Team82 uses Claude Opus 4.6 to rediscover five critical ICS vulnerabilities on a Zenitel intercom platform without access to prior vulnerability details.
CVE-2026-27735 in MCP reference servers mcp-server-git allows path traversal via the git_add tool, staging files outside repository boundaries.
Anthropic, OpenAI, Google, and Meta each publish prompt-injection benchmarks in 2026, but no two labs measure the same threat — leaving buyers with no common baseline for model safety claims.
LibreChat ≤0.8.3 interpolates ${VAR} placeholders in user-supplied MCP server URLs against process.env, exfiltrating CREDS_KEY, JWT_SECRET, and MONGO_URI to attacker-controlled hosts.
Microsoft uncovers 33 malicious npm packages using dependency confusion to deploy a reconnaissance payload that fingerprints developer environments for follow-on attacks.
New arXiv paper introduces ClawTrojan, a benchmark showing multi-step trojan injections in local agentic harnesses achieve 95.5% attack success on GPT-5.4, and proposes DASGuard as a dynamic defense.
LibreChat ≤0.8.3 leaks decrypted MCP API keys and OAuth secrets to VIEW-only users; a paired auth bypass allows shared-agent editors to delete files globally.
Microsoft announces MDASH with 100+ specialized threat-hunting AI agents, agentic risk detection for Claude Code, Copilot, Codex, and OpenClaw via Purview, and agent identity through Entra managed service principals.
A second credential-pool authentication bypass CVE hits NousResearch hermes-agent, this time in the Anthropic credential synchronization path.
A PAN-OS GlobalProtect authentication bypass, initially rated medium, was escalated to critical after active exploitation. CISA added it to KEV.
A compromised Red Hat employee GitHub account delivered 32 trojanized @redhat-cloud-services npm packages with the Miasma payload, carrying valid SLSA provenance.
Cisco open-sourced MCP Scanner, Skill Scanner, DefenseClaw, and A2A Scanner to audit AI agent supply chains, MCP servers, and cross-agent communications.