Skip to content

v1.2.0 β€” MCP Systemic RCE, Mythos/Glasswing, Claude Code Leak (April 2026)

Choose a tag to compare

@cruzgio cruzgio released this 21 Apr 01:05
· 3 commits to main since this release
34d95c2

πŸ”΄ Critical Findings

MCP "Mother of All Supply Chains"

Ox Security uncovered an architectural RCE vulnerability in Anthropic's MCP SDKs β€” not a coding error, but a design decision baked into every supported language (Python, TypeScript, Java, Rust). 150M+ downloads affected, up to 200,000 vulnerable instances.

Claude Mythos Preview & Project Glasswing

Anthropic's unreleased frontier model autonomously discovers thousands of 0-day vulnerabilities across major OS and browsers:

Claude Code Source Leak

On March 31, 2026 Anthropic accidentally published a 59.8 MB source map for Claude Code v2.1.88 to npm:

nginx-ui MCPwn (CVE-2026-33032)

CVSS 9.8, actively exploited in the wild. Full Nginx service takeover in 2 HTTP requests via unauthenticated MCP endpoints. Listed among 31 vulnerabilities actively exploited in March 2026.


🟑 High-Impact Updates


πŸ“¦ New Content

Dorks & Queries

Type Count Highlights
Google Dorks 20+ new MCP configs, Claude Code artifacts, Windsurf, YOLO mode, DeepSeek, Codex
GitHub Dorks 15+ new MCP JSON leaks, YOLO mode configs, AI agent secrets, CLAUDE.md exploitation
Shodan Dorks 8+ new MCP endpoints, Flowise, vLLM, nginx-ui, Open WebUI, LiteLLM, ClickHouse
Censys Queries 8+ new MCP endpoints, vLLM, DeepSeek-style exposure, Flowise, nginx-ui, Langflow

Detection

  • 5 new Sigma rules (Rules 8-12):
    • MCP STDIO arbitrary command execution
    • VS Code Copilot YOLO mode activation (CVE-2025-53773)
    • nginx-ui MCP endpoint exploitation (CVE-2026-33032)
    • DNS-based data exfiltration from AI sandboxes
    • Claude Code 50+ subcommand pipeline bypass

Tools

  • MCPSafetyScanner β€” MCP server security auditing ([GitHub](https://github.com/johnhalloran321/mcpSafetyScanner))
  • Cisco AI Supply Chain Scanners β€” MCP, A2A, pickle, agentic skill file scanners
  • DorkEye β€” Automated Google Dorking with multi-agent analysis
  • Claude Code Security β€” AI-powered static analysis (Anthropic, research preview)
  • ATTESTMCP β€” Protocol extension reducing MCP attack success 52.8% β†’ 12.4%
  • Vulnerable MCP DB updated: now 50 vulns, 13 critical, 32 researchers

Threat Intelligence

  • 10+ new entries covering Mythos, Claude Code leak, MCP systemic RCE, ChatGPT DNS exfil, Copilot YOLO, Codex injection, nginx-ui MCPwn, DeepSeek exposure
  • 12+ new CVEs documented with severity and references
  • 15+ new resources and reports

πŸ“Š Updated Statistics

Metric Previous Updated
Ollama instances exposed 175,000+ 187,000+
ChatGPT creds on dark web β€” 300,000+
MCP supply chain affected β€” 150M+ downloads
MCP vulnerabilities tracked β€” 50 (13 critical)
MCP marketplaces poisoned β€” 9 of 11
Sigma detection rules 7 12
Time-to-exploit average β€” < 20 hours
AI code with vulnerabilities β€” 45%

🏷️ New GitHub Topics

mcp-security Β· ai-supply-chain Β· claude-code Β· project-glasswing Β· llmjacking Β· ai-ide-security Β· copilot-security Β· deepseek-security


πŸ“š Key New References

Source Report
Ox Security MCP Supply Chain Advisory
Anthropic Mythos Preview System Card
Anthropic CVE-2026-2796 Exploit Deep-Dive
IBM X-Force Threat Intelligence Index 2026
Cisco State of AI Security 2026
Check Point ChatGPT DNS Exfiltration
Zscaler Claude Code Leak Analysis
CSA Mythos Exploit Gap Briefing
Wiz Claude Mythos Analysis
LeakIX Ollama Exposed (12,269 instances)