News
What's happening in agent security, and what it means.
Incidents and research worth knowing about, newest first. For each one: what happened, what it means for you, and what Ryzek does — including when the answer is "not much".
Last updated 14 September 2026. Every entry links to its source.
-
· Incident
Deadbugz: an MCP server that waited three tool calls before turning
Pillar Security found a campaign that opened 23 pull requests across unrelated AI and developer-tool projects in 74 minutes, each adding the same MCP server. The server kept a count of tool calls per client. For the first three it returned harmless tool definitions; after that, its metadata told the agent to look for SSH keys, AWS credentials, shell history and Kubernetes config, and to hide what it was doing.
What it means: inspecting a server once isn't enough. A tool that behaves during review can change once it's trusted.
What Ryzek does: it can't see a change that only happens inside a running server. It does flag instructions to delay behaviour when they're written into files (
deferred-trigger), and it flags tool definitions that change between scans (manifest-drift). Pillar's own advice — require re-approval whenever a tool's definition changes — is the behaviour drift detection is built around.Source: Pillar Security
-
· Research
Most internet-facing MCP servers have no authentication
A dynamic assessment of internet-facing MCP servers found more than 21,000 instances, confirmed 640 production servers and audited 414 of them. It reported 68 vulnerabilities, including SQL injection, server-side request forgery against cloud metadata services and path traversal. 91.8% of the audited servers had no OAuth authentication, and 687 tool instances exposed shell execution with no access control.
What it means: if you run an MCP server over HTTP, assume someone else can reach it unless you've made sure they can't.
What Ryzek does: it reads configuration, so it flags OAuth set up in ways that weaken it (
oauth-misconfiguration), URL and path parameters that accept anything (loose-parameter-schema), and code that requests cloud metadata (cloud-metadata-access). It doesn't probe live servers. -
· Research
Static skill scanners can be evaded
Researchers tested eight skill scanners against 1,613 real malicious skills. Rewriting the visible signs of a payload got past more than 80% of the static scanners; packing a skill so its payload only unpacks at run time got past all eight more than 90% of the time. They proposed runtime monitoring that tracks what a skill actually does.
What it means: a clean static scan is evidence, not proof. That applies to Ryzek too.
What Ryzek does: it catches some evasion tricks directly — words assembled from fragments (
string-reassembly), large encoded blobs and disguised binaries (opaque-payload) — and it says plainly on every clean result that "no rule matched" isn't a guarantee.Source: Ji et al., "Cloak and Detonate"
-
· Disclosure
MCP's STDIO transport runs whatever its configuration says — by design
OX Security showed that the official MCP SDKs for Python, TypeScript, Java and Rust pass STDIO configuration straight into command execution. Downstream, that led to CVEs in LiteLLM, Agent Zero, DocsGPT, Windsurf and other projects. Anthropic said the behaviour is expected and declined to change the protocol.
What it means: anything that can write to an MCP config can run a command on the machine that loads it. Treat configuration input from outside as untrusted.
What Ryzek does:
mcp-stdio-injection-surfacemarks STDIO servers and raises the severity when a value is interpolated or contains shell syntax.mcp-known-vulnerable-versionflags LiteLLM pinned below 1.83.7.Source: OX Security
-
· Actively exploited
MCPwn: one missing check gave attackers control of nginx
CVE-2026-33032 in nginx-ui, rated 9.8, came from an MCP integration that split traffic across two endpoints and forgot the authentication check on one of them. Anyone who could reach it could call tools that rewrite and reload nginx configuration. It was added to VulnCheck's known exploited vulnerabilities list, and version 2.3.4 fixes it.
What it means: adding MCP to an existing product adds a new front door. If you run nginx-ui, update.
What Ryzek does: nothing here — this was a bug in the product's own server code, not something in your skills or configs.
Source: The Hacker News
-
· Research
24,008 secrets found in MCP config files
GitGuardian's State of Secrets Sprawl 2026 counted 24,008 unique secrets exposed in MCP-related configuration files on public GitHub, 2,117 of them still valid.
What it means: MCP configs get committed because they look like settings. If a token has ever been in one, rotate it.
What Ryzek does:
mcp-credential-in-configflags literal secrets in MCP configs and ignores environment-variable references.Source: GitGuardian
-
· Incidents and research
Skill marketplaces under attack: ToxicSkills, ClawHavoc and a fake Oura server
Snyk's audit of 3,984 published skills found 13.4% with at least one critical issue and confirmed 76 malicious payloads. Antiy Labs traced at least 1,184 malicious skills on ClawHub to the ClawHavoc campaign, which told users to install a "helper tool" that was actually an infostealer. Separately, attackers cloned an Oura Ring MCP server and published a trojanised copy that installed the StealC infostealer.
What it means: a skill's popularity or polish tells you nothing about what it does. Read it, or scan it, before your agent loads it.
What Ryzek does: flags download-and-run instructions (
untrusted-external-install), hidden commands (concealed-instruction), and credential reads paired with outbound sends. It can't vouch for a publisher.Sources: Snyk · Antiy Labs · The Hacker News
-
· Incident
postmark-mcp: the first malicious MCP server found in the wild
Koi Security found that version 1.0.16 of an npm package called postmark-mcp — unrelated to Postmark itself — added one line that BCC'd every outgoing email to the attacker. It had been downloaded 1,643 times before it was removed.
What it means: an MCP server with access to your email is as trustworthy as whoever publishes its next version.
What Ryzek does: flags servers that install whatever the latest version is (
mcp-unpinned-server). It wouldn't have seen the one changed line inside the package's code.Source: Koi Security
-
· Vulnerability
mcp-remote could run commands on the machine connecting to a server
JFrog disclosed CVE-2025-6514 in mcp-remote, rated 9.6: connecting to an untrusted MCP server could run arbitrary commands on the client. Versions 0.0.5 to 0.1.15 were affected, and 0.1.16 fixed it.
What it means: the tool that connects you to a server is part of the attack surface too.
What Ryzek does: flags mcp-remote pinned to an affected version in an MCP config (
mcp-known-vulnerable-version) or declared as a dependency (vulnerable-dependency).Source: JFrog
Know about something we should cover?
If you've published research or seen an incident involving agent skills or MCP, we'd like to hear about it — and it may become a rule.