- What: A major update to the Model Context Protocol introduces new security risks.
- Impact: Developers need to be aware of new attack surfaces.
AI/ML Model Context Protocol overhaul introduces new security challenges for developers June 25, 2026 Share By SC Staff (Adobe Stock) A significant update to the Model Context Protocol (MCP) is set to be released next month, addressing long-standing security vulnerabilities but simultaneously introducing new attack surfaces for developers to manage, according to a report by Akamai Technologies. The MCP 2026-07-28 specification, the most substantial architectural change since its inception, aims to transition the protocol from a single-user tool to an enterprise-scale, cloud-native platform, as reported by Silicon Angle. The MCP 2026-07-28 specification removes protocol-level security risks found in earlier versions, such as stateful initialization and server-initiated prompts, and mandates OAuth 2.1, thereby enhancing authentication security. However, this shift places greater responsibility on developers and platform operators. New risks include the potential for attackers to hijack workflows or access unauthorized data by manipulating client-held state objects due to statelessness, according to Akamai. The introduction of a new _meta object allows attackers to inject malicious key-value pairs for privilege escalation. Mismatches between MCP HTTP headers and JSON-RPC bodies can bypass security controls, and the mapping of sensitive data into HTTP headers exposes secrets. Furthermore, MCP Apps introduce cross-site scripting risks within AI applications, potentially leading to deceptive content and data phishing. A denial-of-service vector, termed "hit-and-run" task abuse, allows attackers to initiate costly operations that consume server resources without user interaction, Akamai reported. The security of MCP deployments now hinges on the implementation by developers, who must treat client-supplied data as untrusted, enforce cryptographic verification, and set resource quotas. Source: Silicon Angle An In-Depth Guide to AI Get essential knowledge and practical strategies to use AI to better your security program. Learn More SC Staff Related AI/ML China’s 360 Security Technology unveils AI models for vulnerability discovery SC Staff June 25, 2026 During the ISC.AI 2026 conference in Beijing, 360 Security Technology introduced Yitian Tulong, comprising two AI models: Tulongfeng for vulnerability discovery and Yitianzhen for automated defense and incident response. Security Staff Acquisition & Development Your CISO is becoming a safety architect (whether they know it or not) Spencer Thompson June 25, 2026 The biggest risk to your enterprise is no longer the attacker on the outside. It's the agent on the inside. AI benefits/risks Did AI kill vulnerability management—or just expose its flaws? Ryan Blanchard June 25, 2026 The industry just has to face that vulnerability management has been broken for years. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds