vibehacker
News
judd.dev ·

Your MCP server is an attack surface: Deadbugz and a year of CVEs

A Sept 19 write-up argues MCP servers are privileged, often unauthenticated services: Pillar’s Deadbugz campaign used delayed tool-description rewrites to steal credentials after install-time review, and CISA added LiteLLM’s MCP auth bypass to its Known Exploited Vulnerabilities list. Advice: authenticate, least-privilege tools, treat metadata as untrusted, and watch for description drift after approval.

More news

View all

Claude Code: build-eval and hillclimb tune agents without overfitting

Anthropic’s claude api skill adds /claude api build eval (guided eval design in your repo) and /claude api hillclimb (one change per round tuning with a held out set to catch overfitting). On an internal support bench, hillclimb lifted search accuracy from 74.4% to 98.9% while cutting cost to about one fifth…

Anthropic

Claude Code 2.1.285: disable WebFetch, admins lock API providers

Claude Code 2.1.285 (npm Sept 29) adds CLAUDE CODE DISABLE WEB FETCH to turn off WebFetch and a managed allowedProviders policy so admins can lock machines to Anthropic, Bedrock, Vertex, Foundry, or a cloud gateway. It also ships claude desktop , claude plugin configure , and a fix for URL passwords leaking past log redaction…

Mixed News

OpenAI MCP Events: ChatGPT plugins react via signed webhooks

OpenAI’s DevDay MCP Events let ChatGPT plugins subscribe to MCP server updates (messages, comments, status) and trigger automations over verified signed HTTPS webhooks. Servers need MCP 2.0 (protocol 2026 07 28) with events/list, events/subscribe, and events/unsubscribe; polling and streaming aren’t supported…

OpenAI

Spotted something we missed? Start a thread.