Five found the same MCP hole — the protocol itself is the problem

The agent stack keeps discovering that its plumbing trusts the wrong things — and tonight's lead is a security flaw that five unrelated organizations had to patch separately before anyone called it by name.
One vulnerability, five vendors: researchers say MCP's trust model is structurally broken. Independent researcher Syed Anas Mohiuddin has spent four months disclosing what he calls "protocol pivoting" — an attack where an adversary gets in through one protocol, then rides the trust assumptions between protocols to reach capabilities a second protocol was never meant to hand over. The concrete version is usually server-side request forgery: MCP servers treat data crossing the MCP boundary as trusted simply because it came from "inside the system," so prompt-injection-shaped content walks across agent-to-agent boundaries unchallenged. Google, JPMorgan Chase, Weaviate, France's digital-ministry, and Indonesia's Tangerang City government each confirmed and fixed the same SSRF class independently; 16 vendor advisories credit the same researcher, and the flaws carry real CVEs — Google's mcp-toolbox bug (CVE-2026-14540) and a Rapid7 MCP server injection (CVE-2026-97228). Five US federal GSA servers were reported on September 2 and are still open. Not everyone buys the framing: X41's Markus Vervier argues this is just indirect prompt injection, "a simple subclass," not a new class of attack. Even so, the pattern — five orgs patching the same hole because the protocol has no hallway security — is the story. As Rapid7's Douglas McKee put it, each protocol checks its own front door while nobody watches the space in between. Details on the disclosure are in our sources.
ChatGPT is signing fake New Yorker cartoons with real cartoonists' names. Nieman Lab documented more than 15 New Yorker cartoonists whose signatures ChatGPT's image generator reproduces on AI-generated cartoons without permission — starting with Brendan Loper's pen name "BLOPER" on a viral Dolly Parton gag he never drew. OpenAI told Nieman it appreciates "the community flagging bugs and unintended behavior," and after being notified the model began warning that such prompts may violate its guardrails — but the signatures still appeared at publication. The interesting legal angle isn't copyright: Cornell's James Grimmelmann says attribution points toward a right-of-publicity claim instead, and Condé Nast says its OpenAI deal never covered the cartoons anyway. "My name is my name. It felt very much like a violation of my personhood," Loper said.
Etched is fielding funding offers at $40 billion and up — seven weeks after its last round. TechCrunch, citing people familiar with the company, reports incoming bids ranging from $40 billion from top-tier investors to $50 billion from lesser-known backers, against a $21 billion mark set by a $700 million round led by Jane Street in August. The talks are early, terms may change, and Etched declined to comment; the $21 billion baseline itself is independently confirmed by the Wall Street Journal, which also reported that roughly 15% of the 400-person staff previously worked at Nvidia. If the round lands anywhere near the last one, the person familiar with the offers says it would buy up to 3.5 years of runway for what is an unusually capital-hungry bet — full AI hardware systems built around Etched's own inference chips, with $1 billion in claimed orders behind it.
What to watch: whether a second outlet confirms the $40–50 billion number, and whether those still-open federal MCP servers get patched.
Is "protocol pivoting" a new attack class, or is the security community rebranding prompt injection? Tell us in the comments.




