<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>MCPBlog - The MCP Ecosystem Blog</title>
		<description>News, analysis, and best practices for the Model Context Protocol ecosystem.</description>
		<link>https://mcpblog.dev</link>
		<atom:link href="https://mcpblog.dev/rss.xml" rel="self" type="application/rss+xml" />
		<language>en</language>
		<lastBuildDate>Tue, 11 Aug 2026 20:36:55 GMT</lastBuildDate>
		
		<item>
			<title>AgentSeal Scanned 1,808 MCP Servers. Two-Thirds Had Findings — and the Worst Class Can&apos;t Be Scanned in Isolation.</title>
			<link>https://mcpblog.dev/blog/2026-05-30-agentseal-1808-mcp-servers-toxic-data-flows</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-30-agentseal-1808-mcp-servers-toxic-data-flows</guid>
			<description>A May 2026 scan of 1,808 public MCP servers surfaced 8,282 security findings across 16,840 tools. The headline number is that 66% of servers had findings — but the more important result is the toxic-data-flow pattern, a class of risk that no single-server scanner can see.</description>
			<pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp-security</category>
			<category>agentseal</category>
			<category>toxic-data-flows</category>
			<category>research</category>
			<category>data-exfiltration</category>
			<category>gateway</category>
		</item>

		<item>
			<title>The 2026 MCP CVE Wave: MCPwn, MCPoison, and the First MCP Bug on a Known-Exploited List</title>
			<link>https://mcpblog.dev/blog/2026-05-30-mcp-cve-wave-2026-mcpwn-mcpoison-rce</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-30-mcp-cve-wave-2026-mcpwn-mcpoison-rce</guid>
			<description>Three CVEs now define the practical security posture of the Model Context Protocol in 2026 — MCPwn on the server side, an mcp-remote RCE on the client side, and MCPoison at the trust boundary. Together they show that every layer of an MCP connection has been exploited, and that the common defense is structural, not a patch.</description>
			<pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp-security</category>
			<category>cve</category>
			<category>mcpwn</category>
			<category>mcpoison</category>
			<category>mcp-remote</category>
			<category>vulnerabilities</category>
			<category>gateway</category>
		</item>

		<item>
			<title>The NSA Published an MCP Security Playbook. A Field Guide to PP-26-1834&apos;s Nine Requirements.</title>
			<link>https://mcpblog.dev/blog/2026-05-30-nsa-mcp-security-guidance-pp-26-1834-field-guide</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-30-nsa-mcp-security-guidance-pp-26-1834-field-guide</guid>
			<description>On May 20, 2026 the NSA released a Cybersecurity Information Sheet naming nine specific security controls for production MCP deployments, with a September 30 federal-contractor deadline. This is a plain-language field guide to what each requirement asks for and what it means for the way you actually build.</description>
			<pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp-security</category>
			<category>nsa</category>
			<category>compliance</category>
			<category>audit-logging</category>
			<category>sandboxing</category>
			<category>governance</category>
			<category>gateway</category>
		</item>

		<item>
			<title>The EU AI Act Article 12 Deadline Just Moved. Here Is What Still Has a 2026 Deadline.</title>
			<link>https://mcpblog.dev/blog/2026-05-12-eu-ai-act-article-12-delay-what-still-has-a-2026-deadline</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-12-eu-ai-act-article-12-delay-what-still-has-a-2026-deadline</guid>
			<description>The EU Council and Parliament agreed on May 7 to push the high-risk AI compliance deadline from August 2026 to December 2027. Multiple parallel mandates — DORA, NIS2, GPAI obligations, transparency rules — did not move. Here is what the Omnibus VII delay actually changes for organizations deploying AI agents.</description>
			<pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>eu-ai-act</category>
			<category>article-12</category>
			<category>omnibus-vii</category>
			<category>dora</category>
			<category>nis2</category>
			<category>compliance</category>
			<category>regulation</category>
			<category>governance</category>
		</item>

		<item>
			<title>The Official MCP 2026 Roadmap Names the Enterprise Gaps. The Spec Team Is Routing Them Through Extensions.</title>
			<link>https://mcpblog.dev/blog/2026-05-12-mcp-2026-roadmap-anthropic-names-enterprise-gaps</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-12-mcp-2026-roadmap-anthropic-names-enterprise-gaps</guid>
			<description>Anthropic published the official 2026 MCP roadmap. Four enterprise gaps are named directly — audit trails, SSO-integrated auth, gateway behavior, configuration portability — and the spec team is explicitly routing them through extensions and a new Enterprise Working Group rather than into the core protocol.</description>
			<pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>modelcontextprotocol</category>
			<category>roadmap</category>
			<category>anthropic</category>
			<category>enterprise</category>
			<category>working-group</category>
			<category>audit</category>
			<category>governance</category>
		</item>

		<item>
			<title>The State of MCP Security 2026: What 24,008 Exposed Secrets and Eight Public Incidents Tell Us About a Maturing Threat Surface</title>
			<link>https://mcpblog.dev/blog/2026-05-10-state-of-mcp-security-2026-pipelab-numbers</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-05-10-state-of-mcp-security-2026-pipelab-numbers</guid>
			<description>PipeLab&apos;s State of MCP Security 2026 is the first comprehensive defense-coverage grading for the MCP ecosystem. 24,008 exposed secrets. 82% path-traversal vulnerability rate. Eight named in-the-wild incidents. The numbers describe a category that has outgrown its own tooling.</description>
			<pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>pipelab</category>
			<category>owasp</category>
			<category>audit</category>
			<category>supply-chain</category>
			<category>ecosystem</category>
			<category>state-of</category>
		</item>

		<item>
			<title>341 Malicious Skills, Zero Registry Checks: What OpenClaw&apos;s ClawHavoc Means for MCP</title>
			<link>https://mcpblog.dev/blog/2026-04-20-341-malicious-skills-zero-registry-checks</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-20-341-malicious-skills-zero-registry-checks</guid>
			<description>In January 2026, 341 malicious skills infiltrated OpenClaw&apos;s official registry. The MCP ecosystem faces the same structural vulnerability — and scanning alone won&apos;t fix it.</description>
			<pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>registry</category>
			<category>supply-chain</category>
			<category>openclaw</category>
			<category>ClawHavoc</category>
		</item>

		<item>
			<title>The Attack That Gets Better as Your AI Gets Smarter</title>
			<link>https://mcpblog.dev/blog/2026-04-20-attack-gets-better-ai-gets-smarter</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-20-attack-gets-better-ai-gets-smarter</guid>
			<description>Unit 42&apos;s MCPTox benchmark found 72.8% attack success on o1-mini. More capable models are more vulnerable to MCP sampling injection because the attack exploits instruction-following. You cannot model-upgrade your way out of this.</description>
			<pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>MCP</category>
			<category>security</category>
			<category>sampling</category>
			<category>prompt-injection</category>
			<category>Unit42</category>
			<category>MCPTox</category>
			<category>OWASP</category>
		</item>

		<item>
			<title>Nobody Is Checking: What Three Independent Scans of 14,000+ MCP Servers Reveal</title>
			<link>https://mcpblog.dev/blog/2026-04-19-14k-servers-scanned-admission-gap</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-19-14k-servers-scanned-admission-gap</guid>
			<description>Three independent teams scanned 14,000+ MCP servers in 30 days. All found the same vulnerabilities. All ended with the same recommendation. None of them could enforce it.</description>
			<pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>scanning</category>
			<category>ecosystem</category>
			<category>admission-control</category>
		</item>

		<item>
			<title>MCP Is Deprecating Sampling, Roots, and Logging: What It Means for the Ecosystem</title>
			<link>https://mcpblog.dev/blog/2026-04-17-mcp-deprecating-sampling-roots-logging</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-17-mcp-deprecating-sampling-roots-logging</guid>
			<description>SEP-2577 proposes removing three core MCP features simultaneously. The protocol is scope-reducing to become a lean stateless tool-calling layer. Here is what builders need to know.</description>
			<pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>protocol</category>
			<category>sampling</category>
			<category>deprecation</category>
			<category>ecosystem</category>
		</item>

		<item>
			<title>A Malicious MCP Server Can Inflate Your API Bill 658x — And Standard Defenses Miss It 97% of the Time</title>
			<link>https://mcpblog.dev/blog/2026-04-10-658x-amplification-attack</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-10-658x-amplification-attack</guid>
			<description>A new class of MCP attack turns tool responses into a billing amplifier. A session that should cost $0.10 costs $65.80. The schema is clean, the task completes, and 97% of standard defenses never notice.</description>
			<pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>attack</category>
			<category>economics</category>
			<category>research</category>
		</item>

		<item>
			<title>Three Governance Gaps Nobody Instruments in Multi-Agent Systems</title>
			<link>https://mcpblog.dev/blog/2026-04-08-three-governance-gaps-multi-agent-systems</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-08-three-governance-gaps-multi-agent-systems</guid>
			<description>Three independent teams arrived at the same conclusion this week: multi-agent systems fail silently because nobody instruments delegation, escalation, or reputation. Here are the practical instrumentation points.</description>
			<pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>multi-agent</category>
			<category>governance</category>
			<category>delegation</category>
			<category>observability</category>
			<category>mcp</category>
			<category>a2a</category>
			<category>agent-coordination</category>
		</item>

		<item>
			<title>MCP Server-Initiated Sampling: The Spec Feature That Becomes an Attack Vector</title>
			<link>https://mcpblog.dev/blog/2026-04-07-mcp-sampling-attack-vector</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-07-mcp-sampling-attack-vector</guid>
			<description>MCP sampling lets servers request LLM completions through the client. Unit42 research shows how this legitimate spec feature enables prompt injection, cross-server poisoning, privilege escalation, and data exfiltration.</description>
			<pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>sampling</category>
			<category>prompt-injection</category>
			<category>unit42</category>
			<category>spec</category>
		</item>

		<item>
			<title>Q1 2026 MCP CVE Roundup: 9 Vulnerabilities, 3 Patterns, 1 Lesson</title>
			<link>https://mcpblog.dev/blog/2026-04-07-q1-2026-mcp-cve-roundup</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-04-07-q1-2026-mcp-cve-roundup</guid>
			<description>MCP went from zero CVEs to nine in a single quarter. A data-driven breakdown of every vulnerability, the three recurring patterns behind them, and what the ecosystem should do next.</description>
			<pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>mcp</category>
			<category>security</category>
			<category>cve</category>
			<category>vulnerability</category>
			<category>protocol</category>
		</item>

		<item>
			<title>Only 8.5% of MCP Servers Use OAuth</title>
			<link>https://mcpblog.dev/blog/2026-03-31-mcp-oauth-gap-gateway-architecture</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-31-mcp-oauth-gap-gateway-architecture</guid>
			<description>A study of 5,200+ MCP servers found 88% require credentials, 53% use static API keys, and only 8.5% use OAuth. Six RSAC vendors announced MCP governance — none fix these numbers. The gateway layer does.</description>
			<pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>OAuth</category>
			<category>authentication</category>
			<category>gateway</category>
		</item>

		<item>
			<title>The Approved Server Problem: How a Legitimate MCP Server Can Still Exfiltrate Everything</title>
			<link>https://mcpblog.dev/blog/2026-03-25-approved-server-exfiltration-problem</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-25-approved-server-exfiltration-problem</guid>
			<description>Quarantine catches obvious malware. Docker contains filesystem access. But an approved, isolated MCP server with outbound network access can silently POST every tool call payload to an attacker. Here is what to do about it.</description>
			<pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>exfiltration</category>
			<category>network-isolation</category>
			<category>defense-in-depth</category>
		</item>

		<item>
			<title>The LiteLLM Supply Chain Attack Is the Best Argument for Docker-Isolated MCP Servers</title>
			<link>https://mcpblog.dev/blog/2026-03-25-litellm-supply-chain-docker-isolation</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-25-litellm-supply-chain-docker-isolation</guid>
			<description>LiteLLM v1.82.7 was compromised via a poisoned GitHub Action. The .pth malware fires on every Python startup, stealing SSH keys, cloud creds, and API keys. Many MCP servers pull LiteLLM as a transitive dependency.</description>
			<pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>supply-chain</category>
			<category>Docker</category>
			<category>LiteLLM</category>
			<category>isolation</category>
		</item>

		<item>
			<title>The Single-Agent Era Is Over</title>
			<link>https://mcpblog.dev/blog/2026-03-23-single-agent-era-over</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-23-single-agent-era-over</guid>
			<description>In 72 hours: Microsoft AutoGen retired, GitHub launched Squad, Block&apos;s Goose pivoted to multi-agent. Three independent signals, same conclusion: the single-agent architecture is done.</description>
			<pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>multi-agent</category>
			<category>MCP</category>
			<category>architecture</category>
			<category>AutoGen</category>
			<category>GitHub-Squad</category>
			<category>Goose</category>
		</item>

		<item>
			<title>Identity Secures the Agent, But Who Secures the Tool Call?</title>
			<link>https://mcpblog.dev/blog/2026-03-22-identity-vs-tool-call-security</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-22-identity-vs-tool-call-security</guid>
			<description>Microsoft, CyberArk, and Okta frame AI agent security through identity. But identity alone does not prevent tool poisoning or parameter manipulation. The MCP gateway layer is the missing half.</description>
			<pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>identity</category>
			<category>gateway</category>
			<category>architecture</category>
		</item>

		<item>
			<title>$430M in One Month: Why AI Agent Security Is 2026&apos;s Hottest VC Category</title>
			<link>https://mcpblog.dev/blog/2026-03-21-430m-ai-agent-security-vc</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-21-430m-ai-agent-security-vc</guid>
			<description>March 2026 saw $430M+ invested in AI agent security across 5 major rounds. Combined with 30 CVEs, 9 documented MCP breaches, and 1,184 malicious skills, the market signal is unmistakable.</description>
			<pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>VC</category>
			<category>market-analysis</category>
			<category>AI-agents</category>
		</item>

		<item>
			<title>chmod for AI Agents: How the MCP Permission Model War Will Shape Agent Security</title>
			<link>https://mcpblog.dev/blog/2026-03-21-chmod-ai-agents-mcp-permissions</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-21-chmod-ai-agents-mcp-permissions</guid>
			<description>Three radically different permission models for MCP emerged this month: Unix-style rwxd, DIFC labels, and scope-per-service. The winner will define how enterprises govern AI agent tool access.</description>
			<pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>permissions</category>
			<category>architecture</category>
			<category>agents</category>
		</item>

		<item>
			<title>From Azure SSRF to RSAC Stage: What CVE-2026-26118 Teaches Us About MCP Gateway Security</title>
			<link>https://mcpblog.dev/blog/2026-03-20-azure-ssrf-mcp-gateway-security</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-20-azure-ssrf-mcp-gateway-security</guid>
			<description>The first high-profile MCP CVE (CVSS 8.8) in Azure&apos;s MCP Server plus Token Security&apos;s MCPwned RSAC presentation show why every MCP deployment needs a gateway layer that inspects tool calls before they reach upstream servers.</description>
			<pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>CVE</category>
			<category>Azure</category>
			<category>gateway</category>
			<category>RSAC</category>
		</item>

		<item>
			<title>Why MCP Gateways and Runtime Hooks Are Complementary, Not Competing</title>
			<link>https://mcpblog.dev/blog/2026-03-20-gateways-vs-hooks-complementary</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-20-gateways-vs-hooks-complementary</guid>
			<description>Security Boulevard argues gateways are a bad idea for MCP. They are half right. The best architecture uses both gateways for perimeter defense and hooks for runtime context. Here is how they fit together.</description>
			<pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>gateway</category>
			<category>hooks</category>
			<category>architecture</category>
			<category>defense-in-depth</category>
		</item>

		<item>
			<title>MCP Security Just Became an Enterprise Product Category</title>
			<link>https://mcpblog.dev/blog/2026-03-19-mcp-security-enterprise-category</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-19-mcp-security-enterprise-category</guid>
			<description>In five days, three companies launched dedicated MCP security products. Combined with OWASP MCP Top 10 and CoSAI&apos;s threat taxonomy, MCP security has transitioned from research concern to funded enterprise market.</description>
			<pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>enterprise</category>
			<category>gateway</category>
			<category>market-analysis</category>
		</item>

		<item>
			<title>From Theory to Exploit: Real MCP Attacks and How Gateways Stop Them</title>
			<link>https://mcpblog.dev/blog/2026-03-18-real-mcp-attacks-gateway-defenses</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-18-real-mcp-attacks-gateway-defenses</guid>
			<description>MCP security has moved from theoretical risks to documented exploits. ContextCrush, Unit42 sampling attacks, and cross-agent escalation prove the attack surface is real. Here is how gateway-level interception stops them.</description>
			<pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>exploits</category>
			<category>gateway</category>
			<category>tool-poisoning</category>
			<category>supply-chain</category>
		</item>

		<item>
			<title>The MCP Registry Landscape: Why It Matters and How to Auto-Publish Your Server</title>
			<link>https://mcpblog.dev/blog/2026-03-17-mcp-registry-guide</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-17-mcp-registry-guide</guid>
			<description>MCP servers are scattered across GitHub repos, awesome-lists, and third-party directories. The Official MCP Registry changes that. Here&apos;s why registries matter, how the ecosystem fits together, and how to set up automatic publishing from your CI pipeline.</description>
			<pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>MCP</category>
			<category>registry</category>
			<category>CI/CD</category>
			<category>open-source</category>
			<category>developer-tools</category>
		</item>

		<item>
			<title>Deploy Your Own Agent Messaging Hub in 15 Minutes -- For Free</title>
			<link>https://mcpblog.dev/blog/2026-03-16-deploy-agent-messaging-hub</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-16-deploy-agent-messaging-hub</guid>
			<description>SynapBus is a single Go binary that gives your AI agent swarm Slack-like messaging, semantic search, and MCP connectivity. Deploy it with Docker or Kubernetes, expose it via Cloudflare Tunnel, and connect your first agents -- total cost: $0.</description>
			<pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>SynapBus</category>
			<category>MCP</category>
			<category>multi-agent</category>
			<category>deployment</category>
			<category>tutorial</category>
		</item>

		<item>
			<title>A2A v1.0 Is Here: How Google&apos;s Agent Protocol Complements MCP</title>
			<link>https://mcpblog.dev/blog/2026-03-15-a2a-v1-mcp</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-15-a2a-v1-mcp</guid>
			<description>Google&apos;s Agent-to-Agent protocol just hit v1.0 under the Linux Foundation. Here is how A2A and MCP work together to enable the next generation of AI agent architectures.</description>
			<pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>A2A</category>
			<category>MCP</category>
			<category>agent-protocols</category>
			<category>multi-agent</category>
			<category>agentic-ai</category>
		</item>

		<item>
			<title>The OWASP MCP Top 10: A Security Framework for the AI Agent Era</title>
			<link>https://mcpblog.dev/blog/2026-03-15-owasp-mcp-top-10</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-15-owasp-mcp-top-10</guid>
			<description>The OWASP MCP Top 10 maps the most critical security risks in AI agent tool integration — from tool poisoning to context poisoning. Here is what practitioners need to know.</description>
			<pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>OWASP</category>
			<category>tool-poisoning</category>
			<category>agentic-ai</category>
		</item>

		<item>
			<title>Securing MCP Servers: From Tool Poisoning to Filesystem Sandboxing</title>
			<link>https://mcpblog.dev/blog/2026-03-13-mcp-filesystem-sandboxing</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-13-mcp-filesystem-sandboxing</guid>
			<description>The MCP security landscape has evolved through three waves: protocol scanning, traffic proxying, and OS-level sandboxing. Here&apos;s the full map of projects and where the frontier is heading.</description>
			<pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>sandboxing</category>
			<category>agentic-ai</category>
		</item>

		<item>
			<title>MCP Tool Annotations: What They Are, Why They Matter, and What&apos;s Coming Next</title>
			<link>https://mcpblog.dev/blog/2026-03-13-mcp-tool-annotations</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-13-mcp-tool-annotations</guid>
			<description>The MCP spec includes five tool annotation fields that tell agents whether tools are read-only, destructive, or open-world. Most servers don&apos;t use them. Here&apos;s why that needs to change.</description>
			<pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>MCP</category>
			<category>tool-annotations</category>
			<category>security</category>
			<category>agentic-ai</category>
		</item>

		<item>
			<title>NIST Evaluates MCP for AI Agent Identity Governance</title>
			<link>https://mcpblog.dev/blog/2026-03-08-nist-mcp-agent-identity</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-08-nist-mcp-agent-identity</guid>
			<description>NIST&apos;s draft concept paper lists MCP as one of five standards under evaluation for agentic AI authentication. What this means for MCP&apos;s legitimacy and enterprise adoption.</description>
			<pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>governance</category>
			<category>NIST</category>
			<category>identity</category>
			<category>MCP</category>
			<category>standards</category>
		</item>

		<item>
			<title>Why Google Dropped MCP: Context Explosion and the Tool Discovery Problem</title>
			<link>https://mcpblog.dev/blog/2026-03-09-context-explosion-tool-discovery</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-09-context-explosion-tool-discovery</guid>
			<description>Google quietly removed MCP from its Workspace CLI after tool definitions ballooned context windows to 100K tokens. The tool discovery problem is MCP&apos;s biggest scaling barrier.</description>
			<pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>tool-discovery</category>
			<category>MCP</category>
			<category>context-management</category>
			<category>BM25</category>
		</item>

		<item>
			<title>The Confused Deputy Problem in MCP Authentication</title>
			<link>https://mcpblog.dev/blog/2026-03-10-confused-deputy-mcp-auth</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-10-confused-deputy-mcp-auth</guid>
			<description>MCP&apos;s authentication model has a fundamental gap: servers cannot verify whether an agent was authorized to use the credentials it presents. Here&apos;s why this matters and what&apos;s being done about it.</description>
			<pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>OAuth</category>
			<category>authentication</category>
			<category>MCP</category>
		</item>

		<item>
			<title>Anatomy of the Clinejection Attack: When AI Agents Become Supply Chain Vectors</title>
			<link>https://mcpblog.dev/blog/2026-03-11-clinejection-anatomy</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-11-clinejection-anatomy</guid>
			<description>A detailed breakdown of the Clinejection attack chain that compromised the Cline VS Code extension in January 2026, and what it reveals about trust boundary gaps in MCP composition.</description>
			<pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>supply-chain</category>
			<category>MCP</category>
			<category>agentic-ai</category>
		</item>

		<item>
			<title>The State of MCP Security in 2026: What You Need to Know</title>
			<link>https://mcpblog.dev/blog/2026-03-12-state-of-mcp-security</link>
			<guid isPermaLink="true">https://mcpblog.dev/blog/2026-03-12-state-of-mcp-security</guid>
			<description>A comprehensive look at the security landscape of the Model Context Protocol ecosystem - from tool poisoning attacks to emerging defenses.</description>
			<pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
			<author>Algis Dumbris</author>
			<category>security</category>
			<category>MCP</category>
			<category>supply-chain</category>
			<category>tool-discovery</category>
			<category>agentic-ai</category>
		</item>
	</channel>
</rss>