In other news
https://www.theregister.com/2026/04/07/anthropic_all_your_zerodays_are_belong_to_us/
Anthropic are setting themselves up as a cyber arms-dealer, just not in the way you thought
Like the firefighter who moonlights as an arsonist
A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers. The Ox research team says they "repeatedly" asked Anthropic to …
By not releasing Claude Mythos they're reventing developing defenses against it, and they're preventing software producers to fix the problems it brings.
What it DOES do is make it possible to re-open the door with an espionage-addicted US government, and given that that club has just extended FISA I think the signs are pretty clear.
Even Trump's dislike is no match against the US compulsion to spy on everything that moves.
.... rather than laughing up their sleeves
MI5 is racing to bolster the defences of Britain’s most critical companies against the hacking threat posed by a powerful new wave of AI… [eg Anthropic's Mythos and such like] ..... https://www.telegraph.co.uk/business/2026/04/19/labour-mi5-protect-national-infrastructure-from-ai-threat/
FFS ...... really? You’re ‘avin’ a larf, mate, if you think Holywood Palace Barracks’s finest are fighting fit for the future and in any way be adequately enabled to contend with and influence the direction of geopolitical travel today in the Greater IntelAIgent Games Plays which all of your tomorrows so effortlessly bring.
I am not entirely sure about my understanding. Presumably, if I am a normal, unprivileged user on my Linux machine, I will only be able to start an STDIO server with my own privileges. So me running an arbitrary shell command or script does not create a new hole. Am I supposed to understand that my MCP/STDIO server will accept API requests from anyone at all (any local user and, if firewalls permit, any remote user anywhere) with arbitrary commands inside, and will run any such command before retirning any diagnostics? This is what the article and the linked blog seem to imply, but, as I said, it's so fscking weird that I am not entirely certain.
If the above is right then it is more of an API access question (and yes, a command whitelist may also be useful, but may be restrictive, too).
It seems that thinking in terms of "intent" rather than "capabilities" is viral in the AI world, and for security it is horribly enough to be absolutely terrifying. The preferred method to install stuff also seems to be "curl https://www.fubar.com/snafu.sh | sh". Do we need a natural intelligence test to allow creating and operating artificial intelligence tools?
I didn't assume root. I did assume idiocy (as in "anyone who runs this as is is a certified idiot"). The command I quoted hides a link to one actual "download" page (of a very popular AI tool). There is no sudo in that particular case, all I omitted was some curl options (that may vary with your mileage).
Actually, sudo may be counterproductive if the idiot in question is not a sudoer - there will be an error and the installation will fail (and the case will have to be dealt with, with an idiot on the other end of the line).
Of course I understand some idiots will run it as root (and many will run everything as root). But even if not, if the shell script installs malware that only waits to exploit some privilege escalation now or in the future (idiots won't prevent downloading updates from C&C servers, I assume) the result will be equivalent. And even a regular user's creds may cause real damage.
Mmm... Bad form in following up on my own post, but I've just missed the edit window and the most important point deserves to be reiterated.
People who consider this method of installing their software acceptable cannot be trusted to create secure software in the first place.
I suspect the authors are thinking that the LLM may use the stdio interface to run arbitrary commands based on user prompts. This is just the result of giving the LLM access to a shell.
If you were going to use this for anything beyond a local deployment you would have to sandbox the MCP server, presumably using Unix access controls. Even for a local interface you should sandbox the MCP server. Or you could just use the web service interface instead...
I don't see any way to change the MCP protocol to fix this security problem, other than by removing the stdio interface. Perhaps the ox.security team is indulging in some marketing to get attention.
Burroughs' offering has been continuously available for around 65 years[0]. Look up Clearpath/MCP ...
One wonders if this modern thing called MCP will still be around in a couple years. Or months, for that matter.
[0] Yes, MCP pre-dated Tron by a couple decades ...
I’m SHOCKED that moving fast and breaking things is, in fact, breaking things.
Anyone that casts even a passing glance at the entire MCP nonsense should march in the opposite direction sharpish, this issue is just is of the more obvious flaws with this nonsense “protocol”
LLMs are notoriously bad at instruction following, why give it access to anything you can’t afford to lose?
stdio and fixed api keys should be forbidden. two most insecure choices. How much of AI will still function is everything is required to use streaming https and oauth2.? not much. why they exist ? lazy security and easy desktop user implementation .if anything. MCP is insecure by design and far off for enterprise use. still half of the world uses it.. Many bugs exist in MCP and a lot in authentication. when you report bus, github auto closed issues because they might or not beare handled by the team in another hidden tracker. no transparancy and so the issie expires after 7 or 22 days even its a totally valid bug .. M2M client credentials and device authentication oauth2 protocols are not even considered or implemented in hosts. how tokens and keys are securley stored is a big question. MCP sucks in security. it an open playground for hacker if your desktop or server gets compromised..
I spend a significant fraction of my day reviewing reports of vulnerabilities generated by "AI" and lesser tools. Stuff like command line arguments passed into main permitting "injection" attacks etc, and yet here we have one of those very tools with it's pants down around it's ankles taking up the rear from anyone who can open a connection. Bravo.
AI companies eating their own dog food has predictably refined the process down to eating their own dog shit.
I spend a significant fraction of my day reviewing reports of vulnerabilities generated by "AI" and lesser tools. Stuff like command line arguments passed into main permitting "injection" attacks etc, and yet here we have one of those very tools with it's pants down around it's ankles taking up the rear from anyone who can open a connection. Bravo.AI companies eating their own dog food has predictably refined the process down to eating their own dog shit. ...... Roo
Roo, Hi.
Your post avoided any comment on whether the development was a viable invisible and intangible existential threat to the continued predominant responses/reactions/self-destructive leaderships by an historical a priori few, skulking and exercising puppet and muppet strings in the dark shade and dodgy shadows of Earth’s rotten and crumbling inglorious and ignominious geopolitical landscapes with populated stages for mass mainstream media studio manipulation ........ without which they rapidly fade away and forever die.
Would/Does the likes of an Anthropic MCP STDIO Server deliver them or save them from that fate with such as would certainly be lines of strings of alien correction? More than just strange and curious minds would surely give many fortunes to know in order to ensure a right positive outcome/a definitive constructive answer to the prayers of billions/a final solution to abiding unnecessary problems ?????
And now that it has been mooted, will it be suicidal and not just both evil and foolish to try to hinder and stop further developments exploring the benefits and rewards to be associated with and responsible for Functional Gains of Superior Singularities of Greater Future Purpose?
And [would it] it would be wise to realise all the above are rhetorical questions and faits accomplis ‽ .