A stolen long-lived PyPI token turned into two trojanized pantheon-agents releases and eight flagged sibling packages, while a two-request PoC gives anonymous callers Python execution on any unpatched senaite.core lab system. Both are real damage today, not narrative risk.
Underneath them, the MCP-tooling ecosystem keeps failing the same way for a second straight day — Chainlit's unauthenticated MCP command-injection/SSRF pair, mcp-contextforge-gateway's unsandboxed Jinja2, browse-mcp's and consciousness-explorer's unconfined file writes, genieacs-mcp's DNS-rebinding bypass of loopback auth, and utcp-http's unchecked OAuth tokenUrl are seven distinct projects making the same trust-boundary mistake. gRPC Erlang's binary_to_term RCE plus its three-advisory hardening batch, and a Kyverno CEL privilege-escalation bug, round out a day that's unusually heavy on both supply-chain and platform-control-plane risk. CISA's KEV catalog added a Citrix NetScaler memory-safety bug today alongside a batch of five older Red Hat, Microsoft, and .NET-component CVEs — a reminder that active exploitation doesn't require a new vulnerability, just an unpatched old one.
→ Operational priority for the night pull pantheon-agents 0.6.1/0.6.2 off every host before shift end, rotate every credential that machine ever touched, and grep your MCP-tooling deployments for caller-controlled file paths, session IDs, or OAuth tokenUrl fields before the pattern claims an eighth project.