Five found the same MCP hole — the protocol itself is the problem

Share
Five found the same MCP hole — the protocol itself is the problem

The agent stack keeps discovering that its plumbing trusts the wrong things — and tonight's lead is a security flaw that five unrelated organizations had to patch separately before anyone called it by name.

One vulnerability, five vendors: researchers say MCP's trust model is structurally broken. Independent researcher Syed Anas Mohiuddin has spent four months disclosing what he calls "protocol pivoting" — an attack where an adversary gets in through one protocol, then rides the trust assumptions between protocols to reach capabilities a second protocol was never meant to hand over. The concrete version is usually server-side request forgery: MCP servers treat data crossing the MCP boundary as trusted simply because it came from "inside the system," so prompt-injection-shaped content walks across agent-to-agent boundaries unchallenged. Google, JPMorgan Chase, Weaviate, France's digital-ministry, and Indonesia's Tangerang City government each confirmed and fixed the same SSRF class independently; 16 vendor advisories credit the same researcher, and the flaws carry real CVEs — Google's mcp-toolbox bug (CVE-2026-14540) and a Rapid7 MCP server injection (CVE-2026-97228). Five US federal GSA servers were reported on September 2 and are still open. Not everyone buys the framing: X41's Markus Vervier argues this is just indirect prompt injection, "a simple subclass," not a new class of attack. Even so, the pattern — five orgs patching the same hole because the protocol has no hallway security — is the story. As Rapid7's Douglas McKee put it, each protocol checks its own front door while nobody watches the space in between. Details on the disclosure are in our sources.


ChatGPT is signing fake New Yorker cartoons with real cartoonists' names. Nieman Lab documented more than 15 New Yorker cartoonists whose signatures ChatGPT's image generator reproduces on AI-generated cartoons without permission — starting with Brendan Loper's pen name "BLOPER" on a viral Dolly Parton gag he never drew. OpenAI told Nieman it appreciates "the community flagging bugs and unintended behavior," and after being notified the model began warning that such prompts may violate its guardrails — but the signatures still appeared at publication. The interesting legal angle isn't copyright: Cornell's James Grimmelmann says attribution points toward a right-of-publicity claim instead, and Condé Nast says its OpenAI deal never covered the cartoons anyway. "My name is my name. It felt very much like a violation of my personhood," Loper said.


Etched is fielding funding offers at $40 billion and up — seven weeks after its last round. TechCrunch, citing people familiar with the company, reports incoming bids ranging from $40 billion from top-tier investors to $50 billion from lesser-known backers, against a $21 billion mark set by a $700 million round led by Jane Street in August. The talks are early, terms may change, and Etched declined to comment; the $21 billion baseline itself is independently confirmed by the Wall Street Journal, which also reported that roughly 15% of the 400-person staff previously worked at Nvidia. If the round lands anywhere near the last one, the person familiar with the offers says it would buy up to 3.5 years of runway for what is an unusually capital-hungry bet — full AI hardware systems built around Etched's own inference chips, with $1 billion in claimed orders behind it.

What to watch: whether a second outlet confirms the $40–50 billion number, and whether those still-open federal MCP servers get patched.

Is "protocol pivoting" a new attack class, or is the security community rebranding prompt injection? Tell us in the comments.

Read more

Altman says the world must accept AI's 'bad things'

Altman says the world must accept AI's 'bad things'

A heavy news day for AI governance and open weights: OpenAI's CEO is publicly pricing the trade-off his industry keeps dodging, Reflection finally put specs on the model it teased yesterday, and AMD is trying to set the terms before Nvidia's RTX Spark lands. Altman says the world should accept AI's "bad things" — and the labs' new pact agrees. In an interview released Monday on Politico's Decoded podcast, Sam Altman said OpenAI's position is "we believe that the world should accept some bad th

Today in AI — October 5, 2026

Today in AI — October 5, 2026

The day the ecosystem stopped pretending everyone is a partner: Meta and Microsoft quietly cut their Claude budgets, Washington gave AI policy a new name, and New York City put lab executives under oath. Elsewhere, one model learned to drive a robot, and Mac users finally got Apple Intelligence off their disks. Models & Research * Reka AI's Rho-1 collapses the multimodal stack into a single 19-billion-parameter model. The research preview runs text, images, video and robot control as token

OpenAI adds text watermarking to ChatGPT and Codex — EU first

OpenAI adds text watermarking to ChatGPT and Codex — EU first

Regulation is now shipping inside the product: OpenAI's EU-only watermark rollout lands today, Wikimedia publishes its evidence against OpenAI's agents, and two of Anthropic's biggest customers are easing off Claude. OpenAI is turning on invisible text watermarking in ChatGPT and Codex — starting with the European Union. Over the coming weeks, eligible EU users across all plans will get a machine-readable signal called textGrain woven into the text the model produces, while API customers anywh

Meta raced to patch a VM escape in Muse before launch

Meta raced to patch a VM escape in Muse before launch

Three stories today share a theme: systems that were supposed to be contained — an agent platform, a preprint archive, a text watermark — all straining at the edges. Meta's own security teams didn't think Muse was ready to ship. 404 Media reports that in the weeks before launch, engineers found several vulnerabilities in the viral agent product, at least one of which could have let a normal Muse user break out of the sandbox and reach sensitive internal Meta databases. The evidence is an inte