A malicious MCP server could trick an application built on the officialΒ MCP Python SDKΒ into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.
Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said inΒ a technical analysis.
The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.
The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system.
Exchanges keep most
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy hasΒ traced nearly 100 deploymentsΒ of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.
The console stores what the malware collects from each phone,