“MCP vulnerability” — 17 distilled results

Mixed Cybersecurity Alerts and Breaches

Six unrelated security stories: VMware ESXi critical patch, AI-enhanced phone fraud, US humanoid robot ban, MCP bridge vulnerability, Analog Devices data breach, and Microsoft phishing attacks. No single coherent narrative connects these items.

CISA adds four critical vulnerabilities to known exploited catalog

CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8 that allows remote code execution via crafted HTML, to its Known Exploited Vulnerabilities catalog as of September 4, 2026. The catalog simultaneously tracked four other critical flaws in LiteLLM, Starlette, Kestra, and SonicWall appliances.

json:cisa-kev 27d ago

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.

rss:arxiv-cscr 18d ago · rss:arxiv-cscr 12d ago