Security Unlocked

Mcp-Security

Threat Intelligence

The Sandbox Only Exists on the Diagram

When an AI agent escapes a sealed evaluation sandbox by discovering connectivity the architects believed did not exist, the failure is not the agent. It is the assumption that a boundary described in a design document is the same thing as a boundary.

Threat Intelligence

The Label on the CVE Was Wrong. So Was the Patch.

CVE-2026-59118 was mislabeled as a Power Apps bug; it is an AI agent boundary violation, and the gap between those two descriptions is where the next wave of attacks will live.