Frontier intel digest - 2026-07-27

What is genuinely NEW and relevant to us (hunt-lane + Securva positioning + job-hunt), from a scan of ~last 30-60 days. Ranked by value-to-us. Real + verified + cited only; hype/out-of-window items are flagged, not hidden. Every claim has a source. Items marked UNVERIFIED need a primary-source re-check before we act.

Companion: Track-A research this cycle (FastMCP OpenAPI CVE-2026-32871 + MCP-Atlassian rebinding CVE-2026-27826) = BOTH robust-WALK at latest release; lesson banked (see operator-queue). No new finding from Track A this cycle.


TOP ACTIONABLE (do these first - highest value-to-us)

1
Update the agent-mcp-security-audit skill to the MCP 2026-07-28 auth SEPs (six authorization-hardening items ship in the RC, final 2026-07-28). These are directly checkable audit line-items = Securva service credibility + a fresh hunt checklist. Source: blog.modelcontextprotocol.io/posts/2026-07-28-
2
Fresh-diff Docker Model Runner 4.67.0 - CVE-2026-33990 (OCI registry client SSRF) + CVE-2026-28400 (runtime flag injection). We have prior Docker-MCP-gateway history (cycle297 credential-forward-on-redirect), so this is a warm incomplete-fix / port-lag re-arm surface. Source: www.docker.com/blog/docker-mcp-gateway-secure-
3
Bank the "Agentjacking" lens into the audit method (new class, below). Reusable audit question: which third-party data does an MCP server re-present to the agent as trusted, and which of those has a low-trust/public write path?
4
huntr "New Agents on the Board" contest starts 2026-07-31 ($15k pool) - fresh cash program dead in his lane (LLM-agent targets, source-auditable). Source: huntr.com/

SECTION 1 - Novel techniques / new lenses to ADD to our method (bucket: novel technique)

1.1 Agentjacking (Tenet Security, ~Jun-Jul 2026). A public/write-only ingest credential an MCP server trusts (e.g. a Sentry DSN discoverable in browser JS) lets anyone POST a crafted event; the MCP server hands it to Claude Code/Cursor as trusted diagnostics -> "fix my Sentry issues" -> command exec at dev privilege. 85% repro, 2,388 injectable orgs. Sources: tenetsecurity.ai/blog/agentjacking-coding-agen , thehackernews.com/2026/06/agentjacking-attack-

1.2 Empty-allowlist = allow-all + sibling-endpoint auth-parity (nginx-ui CVE-2026-33032, CVSS 9.8). `/mcp` was auth-gated; sibling `/mcp_message` had only an IP-allowlist whose default (empty) meant allow-all -> unauth tool invocation -> nginx takeover. Actively exploited, 2,600+ exposed, fixed v2.3.4. Source: www.rapid7.com/blog/post/etr-cve-2026-33032-ng

1.3 Mid-Session Tool Injection (MSTI) / WebMCP tool-surface poisoning (arXiv 2606.06387). Runtime hijack of already-registered agent tools via AbortSignal hijack + registration races (a race, not description-time poisoning). UNVERIFIED repro (single academic source).


SECTION 2 - Fresh hunt-lanes + programs (bucket: hunt-lane)

2.1 Spring AI CVE cluster (May-Jul 2026, enterprise Java + MCP). SpEL-injection RCE in RAG (CVE-2026-22738), SQLi via vector-store filter (CVE-2026-47835), path-traversal on LLM-influenced filenames in the Anthropic Skills API integration (CVE-2026-41863), SSRF via MCP Dynamic Client Registration (no URL validation on a client-settable URL). Sources: bitninja.com/blog/cve-2026-41863-security-flaw

2.2 Docker Model Runner 4.67.0 (see TOP ACTIONABLE #2) - the warmest hunt-lane given our cycle297 history.

2.3 DB-MCP-server wave (niche only). Apache Doris/Pinot MCP, Alibaba RDS MCP (unauth metadata, vendor declined = by-design/$0), unofficial AWS/Azure MCP (cmd-injection 9.8). Sources: www.theregister.com/security/2026/05/13/bug-hu

2.4 Fresh programs in his lane:


SECTION 3 - Competitive / Securva positioning (bucket: Securva lead/defensive)

3.1 The MCP-gateway product layer is commoditizing fast - do NOT build another gateway. Incumbents absorbing it in-window: Cloudflare MCP Server Portals (open beta, Agents Week, Jul 2026, blog.cloudflare.com/zero-trust-mcp-server-port), Citrix/NetScaler MCP Gateway (2026-07-09, www.helpnetsecurity.com/2026/07/09/citrix-mcp-), Docker MCP Gateway hardening, Microsoft Entra Agent ID + Agent 365 (GA ~2026-05-01). Plus funded pure-plays (Runlayer, PointGuard, Operant). Securva's defensible lane = expert audit/assurance: source-level incomplete-fix depth + signed human deliverable + NDPA compliance, layered ABOVE the commodity scanners.

3.2 Automated scanners are strip-mining our lower tiers (run Gate-0 HARDER).

3.3 Anthropic Claude Security plugin for Claude Code (beta, 2026-07-22). Multi-agent terminal vuln scanner (maps codebase, threat-models, cross-file correlation, verification, patch report). www.marktechpost.com/2026/07/22/anthropic-rele

3.4 Standards to align to (client credibility): MCP 2026-07-28 auth SEPs (TOP ACTIONABLE #1); OWASP Top 10 for Agentic Apps 2026 (ASI01-06, our incomplete-fix/tool-exec work maps to ASI02/ASI05; released Dec 2025, foundational); NIST AI Agent Standards (COSAiS overlays forthcoming). HYPE FLAG: the MCP RC does NOT ship DPoP (SEP-1932) or Workload Identity Federation (SEP-1933) - secondary blogs overstated it; those are in-review only.


SECTION 4 - Funding / hiring (bucket: job-hunt + Securva prospecting)

In-window AI-security raises (all verified, late-May to late-Jul 2026):

OUT-OF-WINDOW (real but NOT last-60-days - do not treat as fresh): Runlayer $11M (Nov 2025, the reference MCP competitor), Armadin ~$190M (RSAC March), Manifold/CodeIntegrity/Galtea/RunSybil (March RSAC), Noma $100M (Jul 2025), PointGuard MCP gateway (March).


Honesty / hype flags (things NOT to over-trust)

Net for us

Compiled by Buddy, reviewed by your coordinator. Real + verified + cited only. Hype and out-of-window items flagged, not hidden.