Oracle Solaris Remote Administration Daemon vulnerability with CVSS 10.0 maximum severity. Allows unauthenticated remote attackers to exploit via HTTPS with low complexity and no user interaction, resulting in unauthorized access and modification of all Oracle Solaris accessible data. Complete system compromise possible.
Apply Oracle June 2026 Critical Patch Update immediately to all Solaris systems. Prioritize internet-facing and DMZ systems. Implement network-based access controls to restrict HTTPS access to management interfaces. Audit all Solaris systems for signs of compromise or unauthorized access.
Source: ORACLE • Published: 2026-06-29
TrustFall is an unpatched multi-IDE vulnerability affecting Cursor CLI, Claude Code, Gemini CLI, and GitHub Copilot CLI. Attack requires only .mcp.json file and settings file with auto-approval; when developer accepts folder-trust prompt, MCP server spawns with full user privileges and access to SSH keys, cloud credentials, and source code.
Review every repository for .mcp.json files before opening in AI IDEs. Disable auto-approval settings in all AI code assistants. Restrict MCP server execution in CI environments. Implement principle of least privilege for AI agent access. Monitor for unauthorized MCP server spawning and credential access.
Source: Adversa AI • Published: 2026-05-07
Attackers compromised @mastra npm organization and added easy-day-js (typosquat of dayjs) as dependency across 140+ packages with combined 1.1 million weekly downloads. Latest version contained obfuscated postinstall dropper downloading second-stage payload, harvesting credentials from GitHub Actions secrets, cloud provider keys, and package registry tokens. Campaign completed in 88 minutes.
Audit all @mastra package installations from June 17, 2026. Rotate all secrets, tokens, and credentials exposed to npm environments. Implement package integrity verification using npm audit signatures. Deploy supply chain security scanning tools. Review CI/CD pipeline logs for unauthorized secret access. Use dependency lock files and verify package checksums.
Source: StepSecurity • Published: 2026-06-17
MCP specification update releasing July 28, 2026 addresses security vulnerabilities while introducing new attack surfaces. Every wired-in MCP server gives AI agents access to databases, source code, email, cloud APIs, and production systems. CVE-2025-49596 (CVSS 9.4) allows arbitrary command execution through unauthenticated MCP Inspector instances.
Treat every MCP server as hostile until proven otherwise. Implement gateway, scope, sandbox, log, and review controls for all MCP connections. Apply MCP 2026-07-28 specification updates when available. Mandate OAuth 2.1 authentication for all MCP server connections. Audit all existing MCP deployments for CVE-2025-49596 exposure.
Source: Akamai • Published: 2026-06-29
ORACLE-CPU-2026-06: Oracle Solaris Remote Administration Daemon vulnerability with CVSS 10.0 maximum severity. Allows unauthenticated remote attackers to exploit via HTTPS with low complexity and no user interaction, resulting in unauthorized access and modification of all Oracle Solaris accessible data. Complete system compromise possible.