
BadHost: The Auth Bypass Lurking in 325M AI Systems
CVE-2026-48710 in Starlette lets a single malformed HTTP header bypass authentication on vLLM, LiteLLM, FastAPI, and every MCP server in production.
They summarize our coverage. We write it.
Newsletters like this one rebroadcast our headlines - often without the full review, the source reading, or the analysis underneath. Our weekly briefing sends the work they paraphrase, straight from the desk, before they get to it.
Free, weekly, no spam. One email every Tuesday. Unsubscribe anytime.

CVE-2026-48710 in Starlette lets a single malformed HTTP header bypass authentication on vLLM, LiteLLM, FastAPI, and every MCP server in production.

Robinhood launched MCP-powered agentic trading in beta on May 27, letting AI agents from Claude and ChatGPT manage stock portfolios for 27.5 million retail customers - while regulators work out who's responsible when it goes wrong.

Gemini Spark is Google's first 24/7 cloud-persistent AI agent - ambitious, genuinely novel, and still rough around the privacy edges.

KPMG and Anthropic signed a global alliance giving all 276,000 employees access to Claude, with a dedicated PE product and a preferred-consultant designation for private equity deployments.

The best AI models for function calling and tool use in 2026 - comparing Claude, GPT-5.4, Gemini, DeepSeek, and local models on BFCL and TAU-bench scores.

Microsoft's enterprise control plane for AI agents ships with strong M365 integration and real security muscle - but critical features are still in preview, and the licensing model is a puzzle.

Google shipped WebMCP as an early preview at I/O 2026, a proposed open web standard that lets websites expose structured tools to browser-based AI agents without DOM scraping or fragile visual automation.

Ten offensive security tools ranked by AI integration depth - from Burp Suite and Legba to Nuclei, Ghidra, Hashcat, BloodHound CE, and Metasploit.

Anthropic has acquired Stainless, the SDK automation startup behind developer tooling used by OpenAI, Google, and Cloudflare, for more than $300 million.

Raindrop's MIT-licensed Workshop streams every token and tool call from your AI agent to a local browser dashboard, then lets Claude Code write and fix evaluations automatically.

Notion 3.5's Developer Platform adds Workers, live database sync, and first-class Claude Code and Cursor support - turning the workspace into an AI agent orchestration layer.

Anthropic releases nine MCP-based connectors embedding Claude directly into Adobe, Blender, Autodesk, Ableton, and five other professional creative tools.