MCP — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
January 28, 2026
Last Seen
July 21, 2026

MCP is a technology platform tracked by ThreatCluster, appearing in 9 threat clusters built from 8 intelligence report mentions.

MCP is a technology platform tracked across 9 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 28, 2026; most recent activity July 21, 2026.

Related Threat Clusters

  • Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild

    A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…

    17 articles · Updated June 9, 2026
  • Critical Flowise RCE Vulnerability Exploited, Thousands of Systems at Risk

    A critical remote code execution (RCE) vulnerability in the Flowise low-code platform, tracked as CVE-2025-59528, is being actively exploited by threat actors. This flaw allows attackers to inject arbitrary JavaScript…

    4 articles · Updated April 7, 2026
  • Google Launches CodeMender to Automate Code Vulnerability Remediation

    On July 21, 2026, Google announced the preview release of CodeMender, a managed AI security agent designed to identify and remediate software vulnerabilities. Integrated into the Gemini Enterprise Agent Platform and AI…

    8 articles · Updated July 21, 2026
  • Zero-Click RCE Vulnerability Discovered in Claude Desktop Extensions

    A zero-click remote code execution (RCE) vulnerability has been identified in Claude Desktop Extensions, allowing attackers to compromise systems through a single Google Calendar event. This flaw affects over 10,000…

    23 articles · Updated February 9, 2026
  • Emergence of Agentic AI Raises Governance and Security Challenges

    In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…

    3861 articles · Updated February 10, 2026
  • Wiz Introduces AI-Powered Security Solutions for Cloud Environments

    Wiz has launched two significant tools, the Wiz Green Agent and Wiz Workflows, to enhance cloud security in AI-driven development environments. The Green Agent acts as a digital investigator, automatically identifying…

    2 articles · Updated July 21, 2026
  • LLMs Targeted in Large-Scale Hijacking Operation

    An operation named 'Operation Bizarre Bazaar' has been identified, where exposed LLMs and MCPs are being hijacked for commercial gain. This operation differs from traditional API abuse as it incurs significant costs due…

    5 articles · Updated January 29, 2026
  • OpenAI Enhances Agents SDK with Sandbox for Safer Development

    OpenAI has released an updated version of its Agents SDK, aimed at helping enterprises build safer AI agents. The new SDK introduces sandboxing capabilities that allow agents to operate in controlled environments,…

    4 articles · Updated April 16, 2026
  • AI-Driven Cyber Threats Emerge with MCP Framework

    Cybersecurity experts report a new evolution in attacker tradecraft leveraging AI technologies, specifically through the use of the open-source MCP framework for large language models (LLMs) and AI agents. This…

    2 articles · Updated February 6, 2026

Recent Intelligence Reports

  • Wiz Green Agent — www.wiz.io · July 21, 2026
  • LiteLLM Flaw Chains to CVSS 10 Unauthenticated RCE — Aiweekly.Co · June 9, 2026
  • Living off the agent: The new tactic hijacking enterprise AI — Thenewstack · May 12, 2026
  • OpenAI Agents SDK Major Update Adds File and Code Execution in Sandboxes — Kucoin · April 16, 2026
  • Hackers exploit a critical Flowise flaw affecting thousands of AI workflows — Csoonline · April 8, 2026
  • Anthropic’s DXT poses “critical RCE vulnerability” by running with full system privileges — Csoonline · February 10, 2026
  • Living off the AI: The Next Evolution of Attacker Tradecraft — Securityweek · February 6, 2026
  • Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation — Bleepingcomputer · January 28, 2026

Frequently asked questions

What is MCP?

MCP is a technology platform tracked by ThreatCluster, appearing in 9 threat clusters built from 8 intelligence report mentions.

Is MCP still active?

The most recent intelligence report mentioning MCP on ThreatCluster is dated July 21, 2026. Activity was first observed January 28, 2026, giving a tracked span from then to July 21, 2026.

What is MCP associated with?

Across ThreatCluster reporting, MCP most frequently co-occurs with Hecker, LiveGamer101, Sakuya, Data Breach, Malware, among 12 tracked related entities.

What are the latest developments involving MCP?

The most significant recent cluster is “Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild” (17 articles · Updated June 9, 2026). MCP appears across 9 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on MCP?

MCP appears in 8 intelligence report mentions across 9 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown