Threat Intelligence Report

TIR-2026-003

The MCP Supply Chain Crisis: protocol design vulnerability exposes 200,000+ AI servers to remote code execution. 10 CVEs assigned, systemic supply chain impact across 150 million downloads.

Full report published on paulholder.com. Analysis covers the OX Security advisory, MCP STDIO command injection vectors, Microsoft and Anthropic server exposure, and protocol-level implications for the AI agent ecosystem.

Get the next threat report

New AI security research, sent when it publishes. No cadence promises, no filler, unsubscribe any time.

This analysis used the same methodology as the AI Agent Security Audit. Book a 15-minute call if you want it run against your stack.