MCP is a technology platform tracked by ThreatCluster, appearing in 9 threat clusters built from 8 intelligence report mentions.
MCP is a technology platform tracked across 9 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 28, 2026; most recent activity July 21, 2026.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
A critical remote code execution (RCE) vulnerability in the Flowise low-code platform, tracked as CVE-2025-59528, is being actively exploited by threat actors. This flaw allows attackers to inject arbitrary JavaScript…
On July 21, 2026, Google announced the preview release of CodeMender, a managed AI security agent designed to identify and remediate software vulnerabilities. Integrated into the Gemini Enterprise Agent Platform and AI…
A zero-click remote code execution (RCE) vulnerability has been identified in Claude Desktop Extensions, allowing attackers to compromise systems through a single Google Calendar event. This flaw affects over 10,000…
In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…
Wiz has launched two significant tools, the Wiz Green Agent and Wiz Workflows, to enhance cloud security in AI-driven development environments. The Green Agent acts as a digital investigator, automatically identifying…
An operation named 'Operation Bizarre Bazaar' has been identified, where exposed LLMs and MCPs are being hijacked for commercial gain. This operation differs from traditional API abuse as it incurs significant costs due…
OpenAI has released an updated version of its Agents SDK, aimed at helping enterprises build safer AI agents. The new SDK introduces sandboxing capabilities that allow agents to operate in controlled environments,…
Cybersecurity experts report a new evolution in attacker tradecraft leveraging AI technologies, specifically through the use of the open-source MCP framework for large language models (LLMs) and AI agents. This…
MCP is a technology platform tracked by ThreatCluster, appearing in 9 threat clusters built from 8 intelligence report mentions.
The most recent intelligence report mentioning MCP on ThreatCluster is dated July 21, 2026. Activity was first observed January 28, 2026, giving a tracked span from then to July 21, 2026.
Across ThreatCluster reporting, MCP most frequently co-occurs with Hecker, LiveGamer101, Sakuya, Data Breach, Malware, among 12 tracked related entities.
The most significant recent cluster is “Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild” (17 articles · Updated June 9, 2026). MCP appears across 9 threat clusters in total, listed above with sources.
MCP appears in 8 intelligence report mentions across 9 deduplicated threat clusters, aggregated from 17,000+ monitored sources.