The New Claw Times

The latest news on OpenClaw, AI agents, and automation

Tag

Articles tagged: mcp

2 articles

News July 30, 2026
3 min read

Ruflo Patches CVSS 10.0 Vulnerability That Gave Attackers Unauthenticated Access to AI Agent Infrastructure Through MCP Bridge

Noma Security disclosed CVE-2026-59726, a CVSS 10.0 flaw in the open-source AI agent platform Ruflo that allowed unauthenticated attackers to execute arbitrary code, steal LLM API keys, hijack agent swarms, and poison persistent AI memory through one HTTP POST to the platform's Model Context Protocol bridge. Ruflo patched within hours. The vulnerability is the first critical exploit targeting the MCP bridge layer specifically, marking a shift in agent security threats from model-layer jailbreaks to infrastructure-layer attacks.

Deep Dive April 16, 2026
8 min read

MCPwn: The First Major MCP Exploit in the Wild Is a CVSS 9.8 That Owns Your Nginx Server in Two HTTP Requests

A critical authentication bypass in nginx-ui's MCP integration is being actively exploited to take over Nginx servers without credentials. CVE-2026-33032, codenamed MCPwn by Pluto Security, exposes 12 MCP tools to any network attacker through a single missing middleware call. The fix was 27 characters. The implications reach every team bolting MCP onto production infrastructure.

← Back to all stories