vibehacker
News
judd.dev ·

Your MCP server is an attack surface: Deadbugz and a year of CVEs

A Sept 19 write-up argues MCP servers are privileged, often unauthenticated services: Pillar’s Deadbugz campaign used delayed tool-description rewrites to steal credentials after install-time review, and CISA added LiteLLM’s MCP auth bypass to its Known Exploited Vulnerabilities list. Advice: authenticate, least-privilege tools, treat metadata as untrusted, and watch for description drift after approval.

More news

View all

Lawsuit: Anthropic, OpenAI, SpaceXAI, Google illegally agreed to slow AI

A class action filed Friday in Northern District of California claims Anthropic, OpenAI, SpaceXAI, and Google violated antitrust law when their CEOs publicly backed Dario Amodei’s Sept 12 call to pace frontier AI. Named plaintiffs who pay for ChatGPT, Claude, Grok, or Gemini say a coordinated slowdown would cut what subscribers get for their money; the labs had not commented by Saturday…

ABC7

Artificial Analysis Coding Agent Index now reports safety refusals

Artificial Analysis’s Coding Agent Index v1.5 (announced Sept 18) now reports safety refusals, splitting blocked zeros from recoverable fallbacks when an agent switches models or continues. The chart sits beside DeepSWE, Terminal Bench 4.0, and SWE Atlas QnA scores so builders can see how often security or terminal work dies on a policy gate…

RuntimeWire

OpenAI puts ChatGPT in Word; Office add-in opens to Free plans

OpenAI launched a ChatGPT sidebar for Microsoft Word that drafts, edits, and reformats inside the open document, with the same add in also covering PowerPoint and Excel. It is available on Free and paid plans (usage limits apply); Business and Enterprise get a two week GPT 5.6 Sol preview through Sept 30…

RuntimeWire

Spotted something we missed? Start a thread.