❌

Normal view

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

29 September 2026 at 06:08
A malicious MCP server could trick an application built on the officialΒ MCP Python SDKΒ into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

28 September 2026 at 18:35
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said inΒ a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

28 September 2026 at 17:42
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

28 September 2026 at 17:38
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy hasΒ traced nearly 100 deploymentsΒ of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

❌