Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AT&T Is Automating Away Jobs—and Its Old Telecom Empire

    September 23, 2026

    Smart glasses are already causing havoc in India

    September 23, 2026

    Viture’s Vonder Glasses Are Meant to Map Your Mind

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AT&T Is Automating Away Jobs—and Its Old Telecom Empire
    • Smart glasses are already causing havoc in India
    • Viture’s Vonder Glasses Are Meant to Map Your Mind
    • AI Models Built From Rat Brains Just Got Closer to Reality
    • Don’t be fooled by this summer of AI hype 
    • Barbara Mazzolai Is Cultivating Sustainability Robotics
    • Three-Year-Old Boy’s Metastatic Cancer Disappears After Two Shots of Experimental Cell Therapy
    • How to Claim Your Cut of Apple’s $250 Million Siri Settlement
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»It wasn’t me • The Register
    Cybersecurity

    It wasn’t me • The Register

    kirklandc008@gmail.comBy kirklandc008@gmail.comApril 19, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    It wasn't me • The Register
    Share
    Facebook Twitter LinkedIn Pinterest Email

    OPINION AI vendors: “You need to use AI to fight AI threats (and do everything else in your corporate IT environment).” Also AI vendors: “That’s not a security flaw; it’s working as intended.”

    This pattern has become increasingly common as the digital hypemeisters tell businesses to use AI to do all the things, especially when it comes to detecting and blocking security issues. That is – until a security flaw exists in the AI itself, and then it’s “expected behavior” or a “by-design risk.” 

    Maybe, if we’re lucky, the AI company at fault will quietly publish new security considerations in its documentation. But the root problem doesn’t get fixed. In some cases – like prompt injection – the vendors can’t really fix the flaw, even if they wanted to.

    A couple of recent examples show how this plays out.

    Researchers recently showed how three popular AI agents that integrate with GitHub Actions can be hijacked to steal API keys and access tokens. The three agents are Anthropic’s Claude Code Security Review, Google’s Gemini CLI Action, and Microsoft’s GitHub Copilot, and all three vendors paid out bug bounties for the discoveries.

    Anthropic paid a $100 bounty, upgraded the critical severity from a 9.3 to 9.4, and updated a “security considerations” section in its documentation. Google paid a $1,337 reward for the finding. And GitHub, after first calling this a “known issue” that they “were unable to reproduce,” ultimately paid a $500 prize to the researchers for their disclosure.

    None of the vendors assigned CVEs or published public security advisories.

    Another bug-hunting team disclosed a design flaw baked into Anthropic’s Model Context Protocol (MCP) that, they said, puts as many as 200,000 servers at risk of complete takeover.

    They “repeatedly” asked Anthropic to patch the root issue, and were repeatedly told the protocol works as intended – despite 10 (so far) high- and critical-severity CVEs issued for individual open source tools and AI agents that use MCP. 

    A root patch, the bug hunters claim, could have reduced risk across software packages totaling more than 150 million downloads and protected millions of downstream users.

    Anthropic’s reasoning for not fixing the flaw? Expected behavior. “This is an explicit part of how MCP stdio servers work and we believe this design does not represent a secure default,” the AI company told the researchers. 

    This means that, yet again, the very messy issue of securing these complex, non-deterministic AI systems gets pushed down the line to IT shops or end users. In this case, that includes any developer using Anthropic’s official MCP software development kit in their apps or open source projects, plus any company bringing this open source code and AI tools into their environment.

    Zooming out even further for a minute: it’s worth noting the total lack of US federal AI regulations over restricting AI companies. That’s despite the fact that one of them (Anthropic) last week warned its latest model is so skilled at finding security flaws that it would be much too dangerous to release it to the public. It’s hard to imagine any other sector in which a company could tell people “our product puts everyone at grave risk” and still be allowed to operate with impunity.

    Something I try to impart to my kids is the idea that being mature and earning trust means taking responsibility for their choices and actions, and owning their mistakes. That includes admitting when they are wrong, fixing their mistakes when possible, and making a course correction so that they can be better next time. 

    All of this “wasn’t-me” behavior from AI companies saying security is someone else’s problem to solve shows a total lack of maturity – or even common decency. One only wonders how long it will be before customers reach the same conclusion. ®

    Register wasnt
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AT&T Is Automating Away Jobs—and Its Old Telecom Empire
    • Smart glasses are already causing havoc in India
    • Viture’s Vonder Glasses Are Meant to Map Your Mind
    • AI Models Built From Rat Brains Just Got Closer to Reality
    • Don’t be fooled by this summer of AI hype 

    AT&T Is Automating Away Jobs—and Its Old Telecom Empire

    September 23, 2026

    Smart glasses are already causing havoc in India

    September 23, 2026

    Viture’s Vonder Glasses Are Meant to Map Your Mind

    September 23, 2026

    AI Models Built From Rat Brains Just Got Closer to Reality

    September 23, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.