The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Inside MCP: defending the runtime layer of agent security · Arcis Blog

First reported 29 May 2026 · 28d ago

Coverage timeline

29 May 2026

Single-source incident — first reported, latest, and curated coincide.

Defenders need controls that can actually refuse malicious tool calls at runtime, not just detect them after the fact, especially as MCP tool-call abuse becomes a real attack surface.

An Arcis blog post argues that agent security has four layers (identity, pre-deploy testing, observability, runtime defense) and that the runtime hot path is structurally underserved. It frames MCP's explicit tool-call contract as enabling runtime defense against agent toolcall injection (their vector V32), applying allowlist/sanitize/refuse techniques at the agent-tool boundary.

Why it matters

Defenders need controls that can actually refuse malicious tool calls at runtime, not just detect them after the fact, especially as MCP tool-call abuse becomes a real attack surface.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS