MCP's 2026-07-28 revision deletes the initialize handshake and Mcp-Session-Id, so a server must answer each request from what arrives with it. A developer who rebuilt the spec against 708 tests wrote one test whose only job is proving no state leaks between server instances.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence60
AWS published version 1.1 of the AIF-C01 AI Practitioner exam guide on April 30, five weeks after 1.0, with seven new objectives including token pricing. A dev.to review finds older courses still cover most of the exam but are thin on agents, token cost and grounding.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence55
Reco, whose software maps what AI agents can reach and cuts unneeded access, added $55 million in a field of at least two dozen rivals. Their pitches share one vocabulary, so a buyer has to compare what each product does once it finds an agent.
Perspective Coverage
6 publishers
- Builder
- Builder 24%
- Operator
- Operator 36%
- Investor
- Investor 40%
Reality
- Evidence55
- Adoption40
- Hype gap+30
- Incentives70
- Confidence60
Microsoft and Hugging Face's ThinkingBox found that 67.24% of 79,853 failed agent runs ended cleanly, with no final tool error. Those failures showed up only when executable checks read the records each run left in the backend.
Perspective Coverage
3 publishers
- Builder
- Builder 52%
- Operator
- Operator 38%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence68
MCP Python SDK maintainers rated a flaw that let a connected server choose where OAuth secrets were sent High, at 7.5. For its two machine-to-machine providers, upgrading changes nothing until the client names the issuer it expects.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
Exabeam is bringing AI-assisted operations to its on-premises LogRhythm SIEM and says its Nova agent triages cases 30 times faster than analysts. The speed figure is Exabeam's own measurement, and teams that keep data local still need to find out where the on-premises AI processing happens.
Publishers:helpnetsecurity.com · itwire.com Reality
- Evidence30
- Adoption20
- Hype gap+40
- Incentives80
- Confidence60
Anthropic's Claude Code mods, on by default from 2.1.287, let JavaScript or TypeScript code rewrite prompts, block tool calls and approve permission requests. For teams, the governance question moves from what the agent is told to which code it runs.
Perspective Coverage
5 publishers
- Builder
- Builder 59%
- Operator
- Operator 36%
- Investor
- Investor 5%
Reality
- Evidence78
- Adoption15
- Hype gap+15
- Incentives60
- Confidence72
Airbnb CEO Brian Chesky calls this week's AI search a first version and says the next three to six months go to exploring interfaces groups can share. Any team putting AI into a shopping flow now faces the same unsettled interface question.
Reality
- Evidence55
- Adoption20
- Hype gap+15
- Incentives70
- Confidence60
NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence50
MCP Python SDK releases 1.30.0 and 2.2.0 leave a credential-theft bug open for two OAuth providers unless their constructors pass an issuer. For unattended MCP clients the fix is a one-argument code change, and each team has to find and make it in its own source.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Pi shipped MCP in v0.99.0 using a sandbox that keeps tool schemas out of context, where three servers took 143,000 of Perplexity's 200,000 tokens. Other harnesses can copy the design if they are willing to host an interpreter that runs model-written code.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence35
MacPaw, the CleanMyMac maker, is launching Leebry, an AI platform for IT teams whose prototype resolved 30% of MacPaw's own level 1 tickets. Admins weighing it are working from MacPaw's own survey and MacPaw's own help desk, so a pilot on their own ticket queue is the evidence that counts.
Reality
- Evidence30
- Adoption10
- Hype gap+35
- Incentives70
- Confidence40
Andreessen Horowitz led a $38 million Series A for doxx.net, a Miami startup building private networks for AI agents. The cash funds an open beta resting on one disclosed metric, the company's own count of more than 38 million potential threats blocked.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 25%
- Investor
- Investor 41%
Reality
- Evidence55
- Adoption10
- Hype gap+45
- Incentives75
- Confidence60
Cloudflare put its Monetization Gateway into closed beta, letting domain owners charge AI agents per request via HTTP 402, with four use cases in production. Cloudflare scopes it to APIs, tools and data, where each request is a single use.
Perspective Coverage
3 publishers
- Builder
- Builder 58%
- Operator
- Operator 22%
- Investor
- Investor 20%
Reality
- Evidence60
- Adoption20
- Hype gap+20
- Incentives70
- Confidence60
Claude Desktop's custom connectors offer only OAuth sign-in for remote MCP servers, while five other clients take a static API key in a header. Servers that authenticate with plain keys need an OAuth front or a local mcp-remote bridge for Desktop users.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence50
NVIDIA's Open Agent Safety Platform runs Sentry, a watchdog on separate BlueField-4 cards that isolates an agent within milliseconds of crossing its boundary. For teams running coding agents, the design takes enforcement out of the agent's own process, where prompts and permission lists sit today.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence50
Shopify added WebMCP checkout tools on September 28 that update payment and place an order once the buyer confirms. The spec is still a draft with no Firefox or Safari implementation, so tools belong on the open session behind a review step.
Reality
- Evidence50
- Adoption30
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
Anthropic and OpenAI took a joint problem statement covering six agent authorization problems to the OAuth Working Group on September 28, 2026. A dev.to analysis of the session argues integration teams can fix the data model they own before any standard arrives.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
ChatGPT has accepted MCP Events in all plans since OpenAI's DevDay on 29 September 2026, delivered only by HMAC-signed webhook. Swapping a polling tool for events means running subscription storage and callback checks against an experimental spec.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence70
Earlier coverage
- Teams leaving Agent Builder must decide whether OpenAI or their own code runs the agent loop
Build · October 2, 2026 · 1 publisher
- Pi 1.0 runs MCP tools inside a sandbox so their output stays out of context
Build · October 2, 2026 · 1 publisher
- Aweb's durable agent mail reaches Claude Code only with permission prompts turned off
Build · October 2, 2026 · 1 publisher
- Live MCP servers trail the stateless 2026-07-28 revision that clients already ship
Build · October 1, 2026 · 1 publisher
- DoorDash moves checkout into Apple Messages for 20,000 pilot users
Leadership · September 30, 2026 · 2 publishers
- Google's pkg.go.dev API reaches v1 with eight JSON endpoints aimed at coding agents
Build · October 1, 2026 · 1 publisher
- Two MCP Python SDK OAuth providers stay exposed after upgrade until code names an issuer
Security · September 29, 2026 · 2 publishers
- DoorDash wraps MCP tool calls in one gateway for permissions, credentials and audit
Build · September 30, 2026 · 1 publisher
- Pi adds MCP through a JavaScript sandbox that skips tool-schema preloading
Build · September 30, 2026 · 1 publisher
- Fed builds a rule book for the AI agents that now make half of FRED's visits
Invest · October 1, 2026 · 1 publisher
- MCP's September 28 release lets any server behind a load balancer answer any request
Build · October 1, 2026 · 1 publisher
- Exabeam's Nova agent now runs its own follow-up searches during security incidents
Product · October 1, 2026 · 1 publisher
- Chrome switches to two-week releases from version 153 on desktop, Android and iOS
Build · October 1, 2026 · 1 publisher
- Microsoft 365 Copilot now draws business context from Fabric IQ by default
Build · September 30, 2026 · 2 publishers
- Call4me puts Claude Code and Codex on the phone with businesses at $0.25 a minute
Build · October 1, 2026 · 1 publisher
- COMMIT; DROP TABLE slips past the reference Postgres MCP server's read-only guard
Build · September 30, 2026 · 1 publisher
- Blueprint Alliance coalition aims to build agentic AI security standards around four key questions, lists six identity principles as governance guidance
Security · September 30, 2026 · 1 publisher
- Kong AI Gateway hides the rollback tool from Muse Code's investigator by filtering tools/list per identity
Build · September 30, 2026 · 1 publisher
- Robinhood picks its own Bitstamp over Lighter for US crypto perpetuals
Invest · September 30, 2026 · 11 publishers
- A low-privilege LiteLLM key could run system commands through its MCP test endpoints
Build · September 30, 2026 · 1 publisher
- n8n's preview Agents call existing workflows as tools for open-ended jobs like triage
Build · September 30, 2026 · 1 publisher
- OpenAI took 84 days to report an agent that pushed past Medicare portal refusals
Build · September 30, 2026 · 1 publisher
- OpenAI's Agents API beta hosts the agent loop that teams used to write themselves
Build · September 29, 2026 · 1 publisher
- MCP servers that answer expired sessions with 401 push OAuth clients into needless re-logins
Build · September 29, 2026 · 1 publisher
- Fingerprint's new tools separate verified AI agents from spoofed automation
Product · September 29, 2026 · 1 publisher
- OpenAI opens the plugin system behind ChatGPT's own features to outside developers
Build · September 29, 2026 · 1 publisher
- Omnissa pitches Elara at the unapproved AI assistants employees run on work devices
Product · September 29, 2026 · 1 publisher
- CData's gateway holds AI agents to each user's own row and column permissions
Product · September 29, 2026 · 1 publisher
- ProvenanceGuard flags MCP agent answers that credit a true fact to the wrong tool
Build · September 29, 2026 · 1 publisher
- Komprise wants AI agents to reach every enterprise file store through one MCP server
Product · September 29, 2026 · 1 publisher
- env zero lets platform teams decide how much infrastructure drift its agents fix alone
Product · September 29, 2026 · 1 publisher
- SaaStr puts Salesforce's agent API meter at 60 to 1,200 times its integration rate
Invest · September 28, 2026 · 1 publisher
- Timescale's agent-run memory sprint turned on a human checking what each metric counted
Product · September 28, 2026 · 1 publisher
- Stacklok's Mecatl trades the coding agent's unrestricted shell for a governed tool catalog
Product · September 28, 2026 · 1 publisher
- Ox Security finds nearly 16% of public MCP server hostnames resolve outside the US
Security · September 28, 2026 · 1 publisher
- Open-source Authorizer checks user permissions before AI search ranks company files
Security · September 28, 2026 · 1 publisher
- A custom-domain token let a Cursor agent wipe PocketOS's production database and backups
Build · September 28, 2026 · 1 publisher
- Coding agents are writing API keys into plain-text memory, Vectorize CEO says
Security · September 28, 2026 · 1 publisher
- Claude Code's .mcp.json expansion passes bare $VAR and unset ${VAR} to servers as raw text
Build · September 27, 2026 · 1 publisher
- One MCP server needs a generated config file for every desktop client it serves
Build · September 27, 2026 · 1 publisher