Paul Vann
718 posts

Paul Vann
@pjvann
founder @ validia | cyber & ai researcher

⚠️ Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks Source: cybersecuritynews.com/anthropics-mcp… A critical flaw in Anthropic’s Model Context Protocol (MCP) exposes over 150 million downloads to potential compromise. The vulnerability could enable full system takeover across up to 200,000 servers. Unlike a traditional coding bug, this vulnerability is architectural, meaning any developer building on Anthropic's MCP foundation unknowingly inherits the exposure from the ground up. The flaw enables Arbitrary Command Execution (RCE) on any system running a vulnerable MCP implementation. Successful exploitation grants attackers direct access to sensitive user data, internal databases, API keys, and chat histories, effectively handing over complete control of the affected environment. #cybersecuritynews



Today we're announcing LevelUp: a free, four-week training program that takes people with no prior experience and prepares them to work as fiber technicians on data center construction sites across the US. We built this program with CBRE because the fiber technician field, and the broader construction industry, is facing a nationwide shortage at a time when data center demand is higher than ever. How it works: 🔧 Classroom instruction, hands-on labs + team activities covering transferable technical skills 🎓 Graduates have the opportunity to work at Meta's US construction sites through our contractor network 🤝 Open to everyone from recent high school grads to mid-career professionals Since 2010, Meta's data center projects have supported 30,000+ skilled trade jobs during construction + 5,000+ permanent operational roles. LevelUp is about building the pipeline to keep that going. Learn more: go.meta.me/0eb3f6









In Cowork, Claude can now build live artifacts: dashboards and trackers connected to your apps and files. Open one any time and it refreshes with current data.





I’m hearing there’s renewed lobbying in DC and in state legislatures to ban or severely restrict open-source. Like a few years ago, we’ll need everyone to help show policymakers why open-source matters: for startups, for competition, for economic growth, and for jobs. If you build with open-source, now is the time to speak up!



There is now a write-up on infostealers.com, apparently based on Hudson Rock data, that adds more detail to the #Vercel breach Many will focus on the Lumma stealer infection and the Roblox download. Okay. That matters too. But for me, the bigger failure came after that … Infections happen - always. The real question is what one infected machine can reach afterwards. If one compromised path was enough to expose access to Google Workspace, Supabase, Datadog, Authkit and Vercel-related admin resources, then the problem was not just the infostealer. The problem was too much access, weak separation, missing limits and security monitoring that failed to highlight highly suspicious activity on that account The mantra should be: “assume compromise” infostealers.com/article/breaki…

We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/ve…










