frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Critical RCE Vulnerability in Anthropic MCP Inspector – CVE-2025-49596

https://www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596
4•abhisek•3h ago

Comments

rvz•3h ago
> The vulnerability stems from the inability of certain browsers to properly handle the IP address 0.0.0.0, which is often assumed to be secure because it points to localhost. Attackers can exploit this flaw by crafting a malicious website that sends requests to localhost services running on an MCP server, thereby gaining the ability to execute arbitrary commands on a developer’s machine.

The 0.0.0.0-day vulnerability is a 19-year old unpatched bug that exists on many browsers [0] that no-one cared about fixing and it's used to infiltrate local services on the user's machine by visiting any website that fetches from https://0.0.0.0/....

So it is really is not a good idea to have MCP servers and proxies running all over the place on your machine and then you get pwned by going to some random website.

Additionally, including data exfiltration, RCEs, and data leakages the "Model Context Protocol" is really one of the worst standards that has ever been designed.

[0] https://www.oligo.security/blog/0-0-0-0-day-exploiting-local...

The Computer Engineering Game

https://chipinsights.substack.com/p/the-computer-engineering-game
1•bharathw30•2m ago•0 comments

Microsoft claims AI diagnostic tool can outperform doctors

https://www.ft.com/content/149296b9-41b6-4fba-b72c-c72502d01800
1•Brajeshwar•8m ago•0 comments

Perfect Match: Your Preferences and Career Opportunities

https://www.leadinginproduct.com/p/perfect-match-your-preferences-and-career-opportunities
1•benkan•10m ago•0 comments

Cheese may be giving you nightmares

https://medicalxpress.com/news/2025-06-cheese-nightmares-scientists.html
2•Gaishan•11m ago•0 comments

Mark Zuckerberg Announces Creation of Meta Superintelligence Labs

https://www.cnbc.com/2025/06/30/mark-zuckerberg-creating-meta-superintelligence-labs-read-the-memo.html
1•nsoonhui•11m ago•0 comments

Stalled funding, canceled grants: How the NIH crisis is affecting Duke

https://www.dukechronicle.com/article/2025/06/duke-university-national-institutes-of-health-cut-cancel-duke-research-nih-federal-funding-grants-trump-administrations
1•nickcotter•13m ago•0 comments

Data breach 2M people's data exposed in ransomware attacks against US retailer

https://www.pcgamer.com/hardware/massive-ahold-delhaize-data-breach-sees-2-2-million-peoples-data-exposed-in-ransomware-attacks-against-major-u-s-food-retailer/
1•Bluestein•14m ago•0 comments

What 3 Years in Tech Taught Me

https://medium.com/geek-talk/what-3-years-in-tech-taught-me-4e8f6e0d5d71
1•kirillwolkow•15m ago•0 comments

Sudoedit(8) – Linux Manual Page

https://www.man7.org/linux/man-pages/man8/sudoedit.8.html
1•thunderbong•16m ago•0 comments

Aging-Related Inflammation Is Not Universal Across Human Populations

https://www.publichealth.columbia.edu/news/aging-related-inflammation-not-universal-across-human-populations
1•XzetaU8•18m ago•0 comments

100k web tool ideas waiting to be built

https://nichetools.net
1•mattmerrick•29m ago•0 comments

Reuleaux Kinematic Mechanisms Collection

https://digital.library.cornell.edu/collections/kmoddl
1•gyomu•30m ago•0 comments

EmailJS

https://www.emailjs.com/
1•9woc•44m ago•0 comments

Flock Safety's Feature Updates Cannot Make Automated License Plate Readers Safe

https://www.eff.org/deeplinks/2025/06/flock-safetys-feature-updates-cannot-make-automated-license-plate-readers-safe
2•nxobject•49m ago•0 comments

Run any LLM locally on your Mac in less than 2 mins

https://www.dsdev.in/run-any-llm-locally-on-your-mac-in-less-than-2-mins
1•dhaval_singh_19•50m ago•0 comments

Is Today Friday?

https://istodayfriday.net/
1•mattmerrick•52m ago•1 comments

China tests hypersonic aircraft Mach 12

https://www.theregister.com/2025/07/01/china_successfully_tests_hypersonic_aircraft/
3•SanjayMehta•1h ago•1 comments

Orchestrating Edge AI Workloads on a Jetson Orin Nano with Nomad

https://atodorov.me/2025/06/27/orchestrating-edge-ai-workloads-on-a-jetson-orin-nano-with-nomad/
2•Bogdanp•1h ago•0 comments

Panthalassa – Ocean-2 [video]

https://www.youtube.com/watch?v=Q7Pmgq2JKbI
1•WatchDog•1h ago•0 comments

AI/ML and Workflow Engineer – Generative AI (Founding Team)

1•HeartStamp•1h ago•0 comments

Monkeys, Typewriters, and Busy Beavers

https://lcamtuf.substack.com/p/monkeys-typewriters-and-busy-beavers
1•weinzierl•1h ago•0 comments

'Unprecedented' alerts in France as blistering heat grips Europe

https://www.bbc.com/news/articles/c5y7781e915o
8•julosflb•1h ago•0 comments

Atomic War or Peace – Einstein (1947)

https://www.theatlantic.com/magazine/archive/1947/11/atomic-war-or-peace/305443/
2•fx18011•1h ago•0 comments

Hi-Res Audio Is Pointless for Everyday Listeners–Here's Why

https://www.howtogeek.com/hi-res-audio-is-pointless-for-everyday-listenersheres-why/
4•axiomdata316•1h ago•0 comments

Remotely Accessing Your Local AI Services with Wake-on-LAN and a Web Proxy

https://theexceptioncatcher.com/2025/07/remotely-accessing-your-local-ai-services-with-wake-on-lan-a-web-proxy/
2•monksy•1h ago•0 comments

Amazon Is on the Cusp of Using More Robots Than Humans in Its Warehouses

https://www.wsj.com/tech/amazon-warehouse-robots-automation-942b814f
5•mrbonner•1h ago•0 comments

Trump tarrifs threaten world economic order

https://www.abc.net.au/news/2025-07-01/trump-tariff-trade-war-experts-warning-four-corners/105470470
12•kreelman•1h ago•3 comments

DeepSeek App Faces Ban in Germany for Illegal Transfer of User Data

https://www.searchenginejournal.com/deepseek-app-faces-ban-in-germany-for-illegal-transfer-of-user-data/550172/
28•nsoonhui•1h ago•2 comments

Tini.la – Easy Link Sharing and Email Capture

https://tini.la
1•EJTheBae•2h ago•1 comments

Gajim 2.3.0

https://gajim.org/posts/2025-06-29-gajim-2.3.0-released/
2•zaik•2h ago•0 comments