MCP gets an enterprise makeover

The Register - Tue, 07/28/2026 - 16:08
The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024, MCP provides a way for AI applications (agents) based on models like GPT-5.6 Sol or Claude Opus 5 to connect to existing data sources, tools, or other applications. It defines how content is exchanged in a client-server architecture. "The new release is MCP’s most important since remote MCP first launched over a year ago," wrote David Soria Parra, a member of technical staff at Anthropic and co-inventor of MCP, in a blog post. "It is a leap in serving scalable MCP servers and takes all the lessons learned over the last 18 months to provide a robust foundation for MCP’s future." The latest version of the specification does away with the legacy stateful architecture, making it more like HTTP services where network requests do not need to retain the state of the session. "Historically, running MCP at scale required sticky routing or shared state to maintain continuity across sessions," explained Caitie McCaffrey, a Microsoft software engineer and core MCP maintainer, in a blog post. "This made large-scale production deployments complex to implement and operate even when the capabilities being exposed were stateless." The revised protocol changes the underlying architecture to eliminate the overhead of managing session state, which allows organizations to run MCP servers behind standard load balancers on existing Kubernetes and DevOps tooling. The version 2026-07-28 release also includes a Specification Feature Lifecycle and Deprecation Policy, because large companies want clear roadmaps and timelines when it comes to software changes. "The goal is a predictable timeline that SDK authors and implementers can plan migrations against when protocol surface area is retired," the documentation explains. The revised spec comes with a new policy that guarantees a minimum period of 12 months between feature deprecation and removal, which should please enterprise engineering teams, since they'll need to make fewer updates to MCP servers. On the security front, the latest spec revision adds Specification Enhancement Proposal (SEP) 2468, which calls for the inclusion and validation of an issuer (iss) parameter in authorization responses. This should help prevent OAuth Mixup Attacks. An attack of this sort can occur when an OAuth client connects to multiple OAuth providers via multiple MCP servers. If an attacker controls one of these servers, the miscreant could potentially obtain an access token or code from one of the other servers. Checking the iss parameter defends against that particular attack vector. Large organizations should also appreciate support for the Enterprise Managed Authorization extension, which makes it possible to manage MCP servers through a central identity provider. Another improvement involves the evolution of tasks – long-running tool calls or batch operations – into an extension. The main benefit is that tasks shift from a blocking request to an asynchronous request. "The payoff is operational resilience at scale," explains McCaffrey. "Because a task is durable and addressed by a stable handle, clients can persist task IDs to durable storage so that polling can resume after a crash or restart — no fragile, long-lived connections held open while waiting for work to finish, which the old blocking model forced on clients and servers that did not want to implement it." Other notable additions include header-based routing and cacheable list results. Some migration cost is expected, particularly for developers who implemented MCP code that relies on session identifiers. ®

FIFA takes corruption to a new level

Daily Kos - Tue, 07/28/2026 - 16:00

The World Cup may be over, but the stench of FIFA corruption remains. That’s little surprise, given the antics of FIFA President Gianni Infantino before and during the World Cup. He sought to ingratiate himself with President Donald Trump, and he’s now continuing his efforts to sully the sport of soccer by putting it all up for sale. In an announcement that seems to have surprised many of…

Source

Categories: Political News

Looks like JFrog's 0-days let OpenAI's models hack Hugging Face

The Register - Tue, 07/28/2026 - 15:01
We now have a better idea of how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman doesn’t outright admit that the JFrog flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, it definitely looks and quacks like a duck - err, frog. Landman says OpenAI's models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the ExploitGym benchmark. “During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday. JFrog Artifactory is a central platform that organizations use to store and distribute all the software artifacts across their supply chains. It supports more than 60 package formats including Docker, Maven, npm, PyPI, Helm, and AI/ML models. OpenAI “responsibly and immediately” disclosed the vulnerabilities to JFrog, Landman continued. “Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike.” On Monday, JFrog released the fixed versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. The Register asked JFrog whether at least some of these were abused by OpenAI’s rogue models to access the internet and compromise Hugging Face, but the DevOps firm isn’t talking. JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre-release model, escaped their testing sandbox during a security evaluation designed to test their cyber capabilities. During this test, the models found a way to access the open internet, then broke into Hugging Face and accessed private information and stole some credentials. “While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,” OpenAI said on July 21. “To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy.” The Register also reached out to OpenAI and asked if JFrog is the vendor referenced in its blog, but did not receive any response. Luckily, your humble vulture is headed to Vegas in a week for Hacker Summer Camp, so we will be sure to test our betting prowess in the appropriate environment. Without guardrails, of course. ®

Bon mercredi #365cafésoupresque

Coffee Lovers - Tue, 07/28/2026 - 15:00




ph @l_e_ba
#365cafésoupresque

Categories: People's Blogs

Fox News host pushes revolting lies to justify ICE killing

Daily Kos - Tue, 07/28/2026 - 15:00

Fox News host Trace Gallagher is trying to justify the killing of a Houston father by immigration agents—the latest example of the network’s central role in propping up the Trump administration’s most atrocious actions. Just a week after the July 7 shooting of Lorenzo Salgado Araujo during a traffic stop, Gallagher said on “Fox News @ Night” that the killing was justified because authorities…

Source

Categories: Political News

ALT

Effin Birds - Tue, 07/28/2026 - 11:05
A painting of a bird beside the text "where has this glorious bullshit been all my life"ALT
Categories: Humor

Pages