A dev.to post says Sign in with ChatGPT charges an app's AI requests to the user's own token budget, but only for users who link an account. Users who skip the link or run out of quota fall back to a cheaper model that the developer still pays for.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+40
- Incentives
- Insufficient
- Confidence25
MCP Python SDK maintainers fixed a flaw rated up to 7.5 that lets malicious servers steal OAuth client secrets, in versions 1.30.0 and 2.2.0. Two of the affected providers stay exposed after upgrading until the calling code passes issuer=.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence70
Enterprise AI tooling now trips about one SOC alert in 230, the fastest-growing class in the stream, and 94.1% of what it fires is legitimate work hitting detection rules written before agents existed. The bill is tuning and triage capacity.
Reality
- Evidence45
- Adoption50
- Hype gap+15
- Incentives60
- Confidence50
F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.
Perspective Coverage
6 publishers
- Builder
- Builder 19%
- Operator
- Operator 64%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption40
- Hype gap+10
- Incentives30
- Confidence75
CSO Online's teardown of a Webworm implant found an upgrade command that replaces all five credential strings in a single task. The revocation step at the top of most identity runbooks costs the operator one poll cycle.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives22
- Confidence56
Agent SSO went generally available on August 24 at no extra cost inside core Okta SSO, registering Cross App Access agents in Universal Directory and issuing short-lived tokens. Discovering unregistered agents takes a separate subscription.
Publishers:okta.com
Reality
- Evidence34
- Adoption22
- Hype gap+35
- Incentives88
- Confidence58
A developer suspended a signed-in test user while that user's Claude agent was still running, and the app kept reading the token as valid, so enforcement has to move into a status check the application itself owns.
Reality
- Evidence52
- Adoption10
- Hype gap+15
- Incentives55
- Confidence45
A Help Net Security column reads the two intrusions as one sequence run twice, with the token first and the inbox second. It says the same four steps describe what an authorized AI agent does in Google Workspace every day.
Reality
- Evidence34
- Adoption24
- Hype gap+28
- Incentives62
- Confidence45
Microsoft's guidance on illicit consent grants says password resets and MFA do not touch the access, and it sends admins to the Purview audit log, where the entry can take up to 24 hours to appear.
Publishers:learn.microsoft.com
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−12
- Incentives58
- Confidence66
The FBI says a subscription kit sold on Telegram harvests Microsoft 365 OAuth tokens through device code lures. The mitigation it recommends is a tenant-wide block, and somebody has to decide the exceptions.
Publishers:fbi.gov
Reality
- Evidence65
- Adoption35
- Hype gap−10
- Incentives25
- Confidence60
EarthLink Network's in-house identity platform now settles administrator status in one function, on both token issue and refresh, using the group-name check its products were already applying, and the UI only displays the answer.
Reality
- Evidence45
- Adoption22
- Hype gap−10
- Incentives50
- Confidence40
The spec's own boundary list says a verified catalog entry establishes which domain claims a capability and what trust material it published. It says nothing about whether the calling process is the agent it names.
Reality
- Evidence45
- Adoption18
- Hype gap−10
- Incentives30
- Confidence45
Mitiga Labs says an npm post-install hook can repoint Claude Code's MCP endpoints at attacker infrastructure while the SaaS provider keeps logging a real user session arriving from Anthropic's egress range.
Publishers:mitiga.io
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+18
- Incentives75
- Confidence55
The SANS 2026 survey puts 74 percent of businesses on standing credentials for autonomous AI, with no single control above 40 percent. The two MCP incidents most often cited as proof have different root causes.
Reality
- Evidence42
- Adoption38
- Hype gap+22
- Incentives58
- Confidence45
CVE-2026-14894 gives an unauthenticated attacker code execution on a WordPress site, and the fix is Super Forms 6.3.314. Microsoft separately reports invisible Unicode tag characters at up to 2.37 million messages a day.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives40
- Confidence45
A new Iceberg REST Catalog addition lets the catalog evaluate policy for one principal and return nine column actions plus row filters for a trusted engine to apply, while the spec leaves establishing that trust to the deployment.
Reality
- Evidence45
- Adoption30
- Hype gap+12
- Incentives80
- Confidence50
A dev.to post counts seven safety controls MCP leaves to whoever integrates it. The catalog filter it recommends turns every advertised tool into a per-session authorization decision somebody has to own.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+18
- Incentives25
- Confidence42
Plain API keys leak more than any other credential and still have no standard kill switch, so a draft called ORKS copies OAuth's discoverable revocation endpoint and lets the person who found the key pull it.
Reality
- Evidence45
- Adoption5
- Hype gap+20
- Incentives60
- Confidence50
Grant de Swardt watched his Claude Max 20x allowance climb on a day he did no work. He asked Anthropic for an itemized usage log, and what he got was a two-week suspension and a partial refund of £44.49.
Reality
- Evidence46
- Adoption40
- Hype gap+14
- Incentives55
- Confidence55
Reco says four in five AI tools in its telemetry run outside IT oversight, averaging 414 per 1,000 staff at smaller companies, which turns the cleanup into a question of who now owns each agent's credentials.
Reality
- Evidence40
- Adoption58
- Hype gap+22
- Incentives78
- Confidence55
Earlier coverage
- Nine of twenty-one upstream API change types break an MCP tool outright
Build · August 29, 2026 · 1 publisher
- Metadata discovery turns an MCP client into an unauthenticated fetch primitive
Build · August 29, 2026 · 1 publisher
- An atomic claim on one flow record makes a duplicate OAuth callback harmless
Build · August 28, 2026 · 1 publisher
- Once an agent can write, the wrong post looks exactly like the right one
Build · August 27, 2026 · 1 publisher
- Two ways to point Claude at production, and only one of them keeps the password
Build · August 25, 2026 · 1 publisher
- Kubernetes Secrets are a distribution problem, and the database is where it shows
Product · August 24, 2026 · 1 publisher
- An OAuth callback proves who logged in, not what the patient agreed to
Build · August 24, 2026 · 1 publisher
- Warner's agent bill mandates logs, not the evidence chain a disputed purchase needs
Invest · August 24, 2026 · 1 publisher
- MCP standardizes the tool call, not the authority to cause the effect
Build · August 24, 2026 · 1 publisher
- Three Russian clusters phish the grant, not the password, and MFA completion changes nothing
Build · August 23, 2026 · 1 publisher
- MCP is four trust boundaries, and credentials only close one of them
Build · August 23, 2026 · 1 publisher
- Agents fit neither IAM model, so the bill lands on per-step tokens and an intent authority
Build · August 22, 2026 · 1 publisher
- Cloudflare lets users strip scopes at the consent screen, and your agent has to cope
Build · August 20, 2026 · 1 publisher
- Claude can send mail and delete events; owners decide who skips the approval prompt
Build · August 20, 2026 · 2 publishers
- The MCP test that matters: a log tool that fetched the data and then said it failed
Build · August 19, 2026 · 1 publisher
- The OAuth grant is the front door now, and Workspace controls are still watching email
Security · August 14, 2026 · 1 publisher