this post was submitted on 17 Apr 2026
68 points (97.2% liked)

Programming

26523 readers
378 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 2 years ago
MODERATORS
 

A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers.

top 5 comments
sorted by: hot top controversial new old
[–] ramble81@lemmy.zip 8 points 1 hour ago

I think the biggest thing that blows my mind about this whole AI rush is that we were finally starting to get security ingrained in people’s minds and have them understand the risks of data exfiltration and reputation damage, even holding companies responsible for data breaches and then….. throw everything out the window with security because AI

[–] MonkderVierte@lemmy.zip 26 points 6 hours ago (1 children)

AI a security risk? Can't be! 🙄

[–] pennomi@lemmy.world 9 points 2 hours ago (1 children)

It’s worse even than that. The server software (released by Anthropic) that lets an AI connect to a web service has a critical arbitrary remote code execution bug. So if you even let an AI connect to you, you’ve now allowed anyone to access your whole server.

There is no excuse for this other than wild incompetence.

[–] fluxx@mander.xyz 4 points 2 hours ago

Wait, but Mythos is the revolution in the software security world, it found 0-days in all popular OS's, including FreeBSD. I'm sure it would have found critical bugs in their own code! /s

[–] kingofras@lemmy.world 7 points 6 hours ago