Your MCP server is an attack surface: Deadbugz and a year of CVEs
A Sept 19 write-up argues MCP servers are privileged, often unauthenticated services: Pillar’s Deadbugz campaign used delayed tool-description rewrites to steal credentials after install-time review, and CISA added LiteLLM’s MCP auth bypass to its Known Exploited Vulnerabilities list. Advice: authenticate, least-privilege tools, treat metadata as untrusted, and watch for description drift after approval.