No new items landed in the six hours since Forenoon Watch, so this synthesis locks in the shape the day already took: two separate trust-boundary failures repeating across unrelated codebases, plus a live authentication bypass on the KEV list connecting one of them to a confirmed exploit.
The clearer pattern is MCP tooling trusting its own transport like localhost: Obot shipped three bugs at once (SSRF to cloud metadata, an unauthenticated registry API, and consent-free OAuth token minting), Process Compose's listener is exploitable via DNS rebinding, and ToolHive's containers can reach the host through host.docker.internal β five unrelated projects, one mistake, the same day. CISA confirms it's not theoretical: BerriAI LiteLLM's MCP endpoint accepting an arbitrary API key as an authenticated session made today's KEV catalog, meaning someone is already exploiting the pattern in production. The second thread is GitHub itself as trusted infrastructure β CrowdSec's disclosure that May's TanStack npm attack led to a 170-repo private-repo breach, Transparent Tribe's new Rust backdoor using private repos for C2, and a fresh Rapuncel infostealer campaign impersonating LastPass Authenticator through SEO'd fake repos all lean on the same assumption that GitHub URLs are inherently safe. AnyIO also picked up a third same-day CVE (a stderr-pipe DoS, joining this morning's TLS-spoofing and privilege-retention bugs), and JFrog Artifactory now has four CVEs on the KEV list within a single month β the most-targeted build-pipeline tool on today's watch.
β Operational priority for the night if you run BerriAI's LiteLLM with MCP support enabled, patch or disable its Streamable HTTP endpoint tonight β it's the only item on today's watch with confirmed active exploitation rather than just disclosed risk.