The Model Context Protocol (MCP) has been updated to a fully stateless design in the 2026-07-28 specification, removing required sessions, the initialize handshake, and the Mcp-Session-Id header so MCP servers can run as standard HTTP services without sticky-session infrastructure. The update also replaces stream-dependent elicitation with Multi Round-Trip Requests, adds MCP-specific HTTP headers for gateway and security controls, and tightens authorization through issuer identification and canonical resource audience handling. Cloudflare said its Agents SDK and Workers OAuth Provider already support the new model, and cited production adoption by Sentry and Linear.
At the same time, major vendors including OpenAI, AWS, Cursor, GitHub, Microsoft, and Vercel backed Agent Plugins 1.0.0, a vendor-neutral format for packaging MCP servers and agent skills for use across clients and runtimes. The push for interoperability comes with growing security concerns: researchers published new Nuclei templates to detect publicly exposed AI agent configuration files such as CLAUDE.md, AGENTS.md, Cursor rules, and vscode-mcp.json, warning that misconfigured web roots can leak internal workflows, tool settings, and project conventions as organizations expand AI agent deployments.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The Model Context Protocol 2026-07-28 specification was released, changing MCP from a stateful protocol to a fully stateless one. The release removed required protocol sessions, the initialize handshake, and the Mcp-Session-Id header, and introduced related SDK updates and deprecations.
Agent Plugins 1.0.0 was released as an open, vendor-neutral package format for portable AI agent extensions, packaging Agent Skills and MCP servers into distributable plugins. The article says Vercel initiated the proposal and that OpenAI, AWS, Cursor, GitHub, and Microsoft backed the standard.
A Nuclei pull request introduced detection templates for publicly exposed AI coding-agent instruction and configuration files such as CLAUDE.md, AGENTS.md, Cursor rules, and .cursor/mcp.json. The submission states the templates validated successfully and matched expected paths in fixture smoke tests.
Cloudflare said its Agents SDK supported the new MCP specification from day one, and that customers and partners had already used the release candidate on Cloudflare before finalization. Cloudflare also said its Workers OAuth Provider implements the new authorization requirements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourceblog.cloudflare.com
Open sourcegithub.com
Open sourcemodelcontextprotocol.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.