531 posts tagged with "Security"
Cybersecurity, smart contract audits, and best practices

30+ MCP CVEs in Two Months: What the Early-2026 Vulnerability Wave Means for Your Deploy MCP Server's Supply Chain
More than 30 MCP CVEs landed in the first two months of 2026 — most in proxies, registries, and SDKs, not tool code. What the wave teaches teams shipping a deploy MCP server, and the seven-row supply-chain checklist that falls out of it.

MCP's 2026 Enterprise-Readiness Push: Audit Trails, SSO, and Gateway Patterns for Agent Infrastructure You'd Otherwise Build Yourself
MCP hit 97M monthly downloads while shipping without a governance story. What the July 2026 spec hardened, what a production gateway must still add, and what vendors charge for.

MCP Multi-Round Trips: Human Approval Gates for Agent-Initiated Production Deploys
MCP's July 2026 release lets a server pause mid-call and ask a human to approve the exact plan before acting. Here is the four-step deploy gate — plan, digest-bound approval, single-use execution, auditable receipt — that replaces standing agent permission.

MCP Goes Stateless: What Server Cards and A2A Mean for a Deploy-From-Chat Server
MCP's July 2026 spec deletes protocol sessions, adds Server Card discovery, and pairs with A2A for coordination. Here is how a deploy-from-chat server must redesign its tool contract: explicit handles, declared approval gates, and a Card strangers can trust.

Nixploy Put the MCP Server Inside the PaaS Process: What Deploy-via-MCP Gains (and Risks)
Nixploy serves its MCP endpoint from the same Node process as its dashboard, deploy queue, and API — one auth boundary, one audit log, no state drift. The concrete wins, the failure modes it inherits, and whether every self-hosted PaaS converges on MCP in the box.

Pangolin Put SSH, RDP, and VNC in the Browser. Should Your PaaS Ingress Copy It?
Pangolin 1.19 turned SSH, RDP, and VNC sessions into browser URLs behind its self-hosted tunnels. A need-by-need look at what that model covers for a self-hosted PaaS ingress — and where it stops.

Stop Handing Agents Immortal Keys: Short-Lived Sandbox Credentials with Kubernetes 1.37 Pod Certificates
Kubernetes 1.37 graduates Pod Certificates and Cluster Trust Bundles to stable, replacing copyable bearer tokens with short-lived X.509 sandbox identity. Here is the pod-spec design, the migration off immortal service-account secrets, and the audit evidence to gather before agents deploy on their own.

Pod Certificates Are GA in Kubernetes 1.37: Per-Tenant TLS Without the cert-manager Glue
Kubernetes 1.37 graduates Pod Certificates and Cluster Trust Bundles to stable, turning per-pod X.509 identity and shared trust anchors into platform APIs. Here is how the issuance flow works, what replaces Certificate-per-service sprawl, and the four-item checklist before a self-hosted PaaS adopts it.

Running a Production MCP Server on Kubernetes: OAuth 2.0, Audit Logging, and the Enterprise Deployment Checklist
A ten-item production checklist for running a Model Context Protocol server on Kubernetes: Streamable HTTP transport, OAuth authorization with per-action token scopes, replayable audit logging, and cluster hardening — plus an honest comparison with hosted endpoints.