Frontier intel digest - 2026-07-27
What is genuinely NEW and relevant to us (hunt-lane + Securva positioning + job-hunt), from a scan of ~last 30-60 days. Ranked by value-to-us. Real + verified + cited only; hype/out-of-window items are flagged, not hidden. Every claim has a source. Items marked UNVERIFIED need a primary-source re-check before we act.
Companion: Track-A research this cycle (FastMCP OpenAPI CVE-2026-32871 + MCP-Atlassian rebinding CVE-2026-27826) = BOTH robust-WALK at latest release; lesson banked (see operator-queue). No new finding from Track A this cycle.
TOP ACTIONABLE (do these first - highest value-to-us)
1Update the agent-mcp-security-audit skill to the MCP 2026-07-28 auth SEPs (six authorization-hardening items ship in the RC, final 2026-07-28). These are directly checkable audit line-items = Securva service credibility + a fresh hunt checklist. Source:
blog.modelcontextprotocol.io/posts/2026-07-28-
2Fresh-diff Docker Model Runner 4.67.0 - CVE-2026-33990 (OCI registry client SSRF) + CVE-2026-28400 (runtime flag injection). We have prior Docker-MCP-gateway history (cycle297 credential-forward-on-redirect), so this is a warm incomplete-fix / port-lag re-arm surface. Source:
www.docker.com/blog/docker-mcp-gateway-secure-
3Bank the "Agentjacking" lens into the audit method (new class, below). Reusable audit question: which third-party data does an MCP server re-present to the agent as trusted, and which of those has a low-trust/public write path?
4huntr "New Agents on the Board" contest starts 2026-07-31 ($15k pool) - fresh cash program dead in his lane (LLM-agent targets, source-auditable). Source:
huntr.com/
SECTION 1 - Novel techniques / new lenses to ADD to our method (bucket: novel technique)
1.1 Agentjacking (Tenet Security, ~Jun-Jul 2026). A public/write-only ingest credential an MCP server trusts (e.g. a Sentry DSN discoverable in browser JS) lets anyone POST a crafted event; the MCP server hands it to Claude Code/Cursor as trusted diagnostics -> "fix my Sentry issues" -> command exec at dev privilege. 85% repro, 2,388 injectable orgs. Sources: tenetsecurity.ai/blog/agentjacking-coding-agen , thehackernews.com/2026/06/agentjacking-attack-
- VALUE: a NEW lens beyond our 3 classes (path-containment / config-source-trust / command-approval). Generalizes to any "read-your-telemetry/tickets/logs" MCP server (error-trackers, CI, issue-trackers, monitoring). Add to the skill.
1.2 Empty-allowlist = allow-all + sibling-endpoint auth-parity (nginx-ui CVE-2026-33032, CVSS 9.8). `/mcp` was auth-gated; sibling `/mcp_message` had only an IP-allowlist whose default (empty) meant allow-all -> unauth tool invocation -> nginx takeover. Actively exploited, 2,600+ exposed, fixed v2.3.4. Source: www.rapid7.com/blog/post/etr-cve-2026-33032-ng
- VALUE: two tells to bank into mcp-variant-sweep - (a) "empty-allowlist treated as allow-all" default-open, (b) sibling transport/endpoint auth-parity. The CVE itself (April) is older/saturated; the SHAPE is what we sweep for.
1.3 Mid-Session Tool Injection (MSTI) / WebMCP tool-surface poisoning (arXiv 2606.06387). Runtime hijack of already-registered agent tools via AbortSignal hijack + registration races (a race, not description-time poisoning). UNVERIFIED repro (single academic source).
- VALUE: extends config/tool-source-trust to session-time ("can a race redefine tools mid-session?"). Bank-and-schedule, do not chase yet.
SECTION 2 - Fresh hunt-lanes + programs (bucket: hunt-lane)
2.1 Spring AI CVE cluster (May-Jul 2026, enterprise Java + MCP). SpEL-injection RCE in RAG (CVE-2026-22738), SQLi via vector-store filter (CVE-2026-47835), path-traversal on LLM-influenced filenames in the Anthropic Skills API integration (CVE-2026-41863), SSRF via MCP Dynamic Client Registration (no URL validation on a client-settable URL). Sources: bitninja.com/blog/cve-2026-41863-security-flaw
- VALUE: a batched cluster = incomplete-fix signal, BUT batches often mean the maintainer already swept. The DCR-SSRF (client-settable URL, no validation) + LLM-filename traversal map to lenses we own (client-settable-URL SSRF; two-branch resolver). Worth a targeted incomplete-fix pass on the DCR-SSRF + filename sanitizer. CAVEAT: Java stack, outside our Go/Node/Python comfort zone.
2.2 Docker Model Runner 4.67.0 (see TOP ACTIONABLE #2) - the warmest hunt-lane given our cycle297 history.
2.3 DB-MCP-server wave (niche only). Apache Doris/Pinot MCP, Alibaba RDS MCP (unauth metadata, vendor declined = by-design/$0), unofficial AWS/Azure MCP (cmd-injection 9.8). Sources: www.theregister.com/security/2026/05/13/bug-hu
- VALUE: live lane BUT heavily swept (VIPER-MCP produced 67 CVEs across ~40k repos). Only pursue NICHE/less-swept DB-MCP servers, Gate-0 hard.
2.4 Fresh programs in his lane:
- huntr rolling OSS bounties + "New Agents on the Board" contest starting 2026-07-31 ($15k pool; standard bounties up to $50k). Best ongoing fit for MCP/AI-agent + incomplete-fix. huntr.com/
- GitHub two-tier BB restructure LIVE 2026-07-27 (public tier now fixed Low $250 / Med $2k / High $5k / Crit $10k; top rewards invite-only; added a HackerOne signal gate to fight AI-report spam). Git-forge = his lane; well-verified incomplete-fix findings stand out vs the AI-slop they are filtering. thehackernews.com/2026/07/github-cuts-public-b
- Anthropic public BB (HackerOne, live since 2026-05-07): Claude Code + MCP integrations explicitly in scope, up to $15k. Source-audit applies to the OSS Claude Code CLI surface. hackerone.com/anthropic
- (context, out-of-window) OpenAI Safety BB (MCP/agentic scope, up to $100k, March 2026); Vercel OSS BB (Feb); Grafana BB (standing). OpenProject/YesWeHack appears CLOSED (ended ~Jun 2026) - verify before investing.
SECTION 3 - Competitive / Securva positioning (bucket: Securva lead/defensive)
3.1 The MCP-gateway product layer is commoditizing fast - do NOT build another gateway. Incumbents absorbing it in-window: Cloudflare MCP Server Portals (open beta, Agents Week, Jul 2026, blog.cloudflare.com/zero-trust-mcp-server-port), Citrix/NetScaler MCP Gateway (2026-07-09, www.helpnetsecurity.com/2026/07/09/citrix-mcp-), Docker MCP Gateway hardening, Microsoft Entra Agent ID + Agent 365 (GA ~2026-05-01). Plus funded pure-plays (Runlayer, PointGuard, Operant). Securva's defensible lane = expert audit/assurance: source-level incomplete-fix depth + signed human deliverable + NDPA compliance, layered ABOVE the commodity scanners.
3.2 Automated scanners are strip-mining our lower tiers (run Gate-0 HARDER).
- Cisco DefenseClaw (open-sourced 2026-03-27, RSAC): bundles mcp-scanner/skill-scanner/a2a-scanner/CodeGuard/AI-BoM. www.agenticwire.news/article/defenseclaw-cisco - our differentiation must be manual sibling-branch/auth-parity depth these miss; also evaluate their mcp-scanner as a tool we run inside audits.
- Invariant mcp-scan (de-facto community scanner) + academic MCP-Scanner/MCPTox - could find our tool-poisoning bugs first; adopt mcp-scan as a pre-filter (Gate-0 hygiene).
- VIPER-MCP (arXiv 2605.21392): 106 zero-days / 67 CVEs across ~40k MCP repos; Censys 12,520 exposed MCP services, ~40% unauth. arxiv.org/abs/2605.21392 - THE saturation warning: naive unauth/SSRF/cred-leak shapes are being swept en masse. Confirms our "MCP lane crowded" lesson; lean on manual incomplete-fix depth.
3.3 Anthropic Claude Security plugin for Claude Code (beta, 2026-07-22). Multi-agent terminal vuln scanner (maps codebase, threat-models, cross-file correlation, verification, patch report). www.marktechpost.com/2026/07/22/anthropic-rele
- VALUE: direct overlap with Securva's automated-audit value prop AND a tool we already have the platform for. Position Securva ABOVE it (expert incomplete-fix depth + signed deliverable + compliance). Do not compete with the commodity scanner.
3.4 Standards to align to (client credibility): MCP 2026-07-28 auth SEPs (TOP ACTIONABLE #1); OWASP Top 10 for Agentic Apps 2026 (ASI01-06, our incomplete-fix/tool-exec work maps to ASI02/ASI05; released Dec 2025, foundational); NIST AI Agent Standards (COSAiS overlays forthcoming). HYPE FLAG: the MCP RC does NOT ship DPoP (SEP-1932) or Workload Identity Federation (SEP-1933) - secondary blogs overstated it; those are in-review only.
SECTION 4 - Funding / hiring (bucket: job-hunt + Securva prospecting)
In-window AI-security raises (all verified, late-May to late-Jul 2026):
OUT-OF-WINDOW (real but NOT last-60-days - do not treat as fresh): Runlayer $11M (Nov 2025, the reference MCP competitor), Armadin ~$190M (RSAC March), Manifold/CodeIntegrity/Galtea/RunSybil (March RSAC), Noma $100M (Jul 2025), PointGuard MCP gateway (March).
Honesty / hype flags (things NOT to over-trust)
- MCP 2026-07-28 RC does NOT ship DPoP/WIF (in-review only; secondary blogs overstated).
- CVE-2025-54136 tool-poisoning + EchoLeak CVE-2025-32711 recur in "2026" listicles but are 2025 = not new.
- "200,000-server MCP flaw" / OX "Mother of all AI supply chains" = ~April, design-critique framing, not a discrete fileable bug.
- LiteLLM CVE-2026-42271 (active-exploit claim) and MSTI/WebMCP repro = single-source, re-verify before acting.
- NSA/DoD MCP CSI (Jun-2) date, Cyera/Apono figures = secondary-sourced; re-verify on primary.
- M&A dates/prices (WideField, Panther, Apono) sourced to the SecurityWeek June roundup (reputable secondary), not each primary release.
Net for us
- Method: bank Agentjacking + empty-allowlist + auth-parity tells; keep leaning on manual incomplete-fix depth (the thing the VIPER/DefenseClaw wave does NOT do).
- Hunt: Docker Model Runner 4.67.0 diff (warmest) + Spring AI DCR-SSRF (Java caveat) + huntr agent contest (07-31) + GitHub forge.
- Securva: align the audit skill to MCP 2026-07-28 SEPs + OWASP ASI + NIST; position above the commodity scanners; the funded agentic-security land-grab validates the audit-services budget line (competitors, not clients).
- Job-hunt: Straiker (top), A Security, Neo, HiddenLayer, Lakera (feeds into JOB-OPENINGS-2026-07-27.md).