⚠️ Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks
Source: https://t.co/7ghzzZJBKg
A critical flaw in Anthropic’s Model Context Protocol (MCP) exposes over 150 million downloads to potential compromise. The vulnerability could enable full system takeover across up to 200,000 servers.
Unlike a traditional coding bug, this vulnerability is architectural, meaning any developer building on Anthropic's MCP foundation unknowingly inherits the exposure from the ground up.
The flaw enables Arbitrary Command Execution (RCE) on any system running a vulnerable MCP implementation. Successful exploitation grants attackers direct access to sensitive user data, internal databases, API keys, and chat histories, effectively handing over complete control of the affected environment.
#cybersecuritynews
@sunsamaHQ switched to new Android device and now the Android app fails to start with "TypeError: Cannot read property 'fetchUpdateAsync' of undefined". Re-installing app does not solve the issue. I seem to be a beta tester in Play Store. Known issue?
Really @Finnair, 30 to 40 days at worst? My cases have been pending for over 10 weeks while colleague got a response from same flights in about a week and did the reclaim after me. https://t.co/75fSUERq6f
Today, Kagi celebrates over 50,000 paying subscribers! 🎊
Check out our latest blog post for exciting updates, including the free Kagi Search portal, Kagi for Libraries, new swag and stickers:
https://t.co/DkpmeMCacB
Kagi prioritizes quality, trust, and human relevance in search - no SEO spam, no ads, no synthetic noise.
We also depend entirely on word-of-mouth marketing and community recommendations. Every mention you make to friends and family has a real impact.
Please keep spreading the good word 🙏
@Superhuman Play Store screenshots indicate calendar availability for Android, but that does not seem to be present on the app though. Should it be there?
Is your web browser a snitch?
sizeof(cat)'s independent test on which browsers "phone home" the most on first run:
Kagi Orion, Tor, Pale Moon = 0 connections 🎉
High counts: Zen (82), Edge (48), Floorp (42), Opera (31), FF (29), Chrome (25)
Full report: https://t.co/5v78wVprva
@Superhuman is there a way to exclude eg. certain senders from auto labeling? For example pitch catches expected offers, while those should get through to inbox.