Security Intelligence | March 28, 2026
MCP Security Research in 2026: What the Papers Actually Agree On
The MCP conversation is moving fast, but the research signal is already clearer than the hype. Recent papers on audits, ecosystem attacks, malicious tools, and enterprise mitigations now point to the same conclusion: tool interoperability without policy discipline is fragile by default.
6 min read
Security Intelligence | March 27, 2026
MCP Permission Boundaries in 2026: How to Stop Tools from Becoming Your Weakest Link
Tool-using AI apps are powerful, but the real risk is not the model alone. It is the invisible handoff between prompts, tools, permissions, and human approval. This playbook maps the boundary correctly.
4 min read
Security Intelligence | March 27, 2026
Skill Files Are the New Prompt Injection Surface in 2026
User prompts are no longer the only place agents get poisoned. New benchmark work and recent security papers show that skill files, tool instructions, and agent-side context packages are now a serious injection surface.
3 min read
Security Intelligence | March 27, 2026
Your Multilingual RAG Stack Still Has a Trust Problem in 2026
Cross-lingual retrieval still breaks in subtle ways. Recent research keeps showing the same pattern: multilingual RAG systems can prefer the query language, mishandle conflicting context, and quietly hide better evidence in another language.
3 min read