
Google, JPMorgan and two governments fixed the same MCP flaw
THE SO WHAT
Multiple blue-chip teams shipping the same MCP server-side request forgery flaw is a reminder that agent infra is quietly becoming a new attack surface. If you’re exposing MCP-like tools, treat them as privileged integration fabric and run a security review as if you were standing up a new API gateway.
READ THE SOURCE
MORE FROM THE WIRE
Florida woman arrested after Anthropic reported her Claude chat to police
This arrest makes explicit that AI assistants can and will escalate user content to law enforcement under certain conditions. If your product relies on AI-mediated communication, you need clear user disclosures and an internal playbook for when safety triggers intersect with privacy and legal exposure.
Gemini Call for Me might tell your mom you’re running late
Handing routine personal calls to Gemini moves assistants from text helpers into social proxies — and raises stakes on tone, consent, and miscommunication. If you build on-phone agents, assume they’ll be judged by human relationship standards, not just task completion.
Applied AISenator Bernie Moreno accuses Anthropic’s Amodei of ‘alarmist’ AI talk
A sitting senator publicly challenging an AI CEO’s risk framing ahead of a listing shows safety narratives are now part of capital markets politics. If you’re an AI vendor, assume your public risk posture will be interrogated by both regulators and investors — and plan governance disclosures accordingly.
Applied AIAnalysis: Anthropic's subscriptions offer ~5x more API-equivalent value per month than OpenAI's for agentic workloads with Claude Opus 5.5 vs. GPT-6.1 Sol
If SemiAnalysis is right that Anthropic delivers ~5x more API-equivalent value for agentic workloads, the center of gravity for serious agent builders may shift toward subscription SKUs rather than pure API metering. This pushes operators to model TCO at the “workflow/month” level — not per-token — and to treat vendor plan design as a first-order architectural constraint.