Threat Intelligence Report
TIR-2026-003
The MCP Supply Chain Crisis: protocol design vulnerability exposes 200,000+ AI servers to remote code execution. 10 CVEs assigned, systemic supply chain impact across 150 million downloads.
Full report published on paulholder.com. Analysis covers the OX Security advisory, MCP STDIO command injection vectors, Microsoft and Anthropic server exposure, and protocol-level implications for the AI agent ecosystem.
Get the next threat report
New AI security research, sent when it publishes. No cadence promises, no filler, unsubscribe any time.
This analysis used the same methodology as the AI Agent Security Audit. Book a 15-minute call if you want it run against your stack.