Cloudflare has introduced WriteGuard, a private beta security layer for Model Context Protocol (MCP) servers that intercepts agent requests, enforces tool-specific policies, and logs blocked or failed actions for centralized auditing. The service is designed to curb the risk of AI agents using existing OAuth-backed access to perform sensitive write operations across databases, internal APIs, GitHub, GitLab, Jira, Google Workspace, SaaS platforms, and internal wikis. Cloudflare said WriteGuard can apply consistent controls across multiple MCP servers without requiring changes to each server, while preserving attribution by tying MCP client and session context to the human user and scrubbing sensitive values before audit events are stored.
The launch comes as MCP-connected tools are gaining direct write access to production workflows. ElevenLabs recently introduced a hosted MCP connector that lets Claude inspect and modify ElevenAgents configurations, including changing prompts, voices, languages, retrieving transcripts, generating sample speech, estimating costs, and even deleting agents from a chat interface. ElevenLabs said it uses OAuth plus organization- and session-level controls and urged users to review tool calls before approval, warning that approval alone does not guarantee safe or correct downstream behavior; the company also pointed teams to testing, versioning, and CLI/API-based rollout practices for stronger governance.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
On Monday, ElevenLabs introduced a hosted MCP connector that gives Claude read and write access to ElevenAgents in an authenticated workspace via OAuth. The connector lets developers inspect and modify agent configurations, estimate change costs, and perform actions including transcript retrieval and agent deletion, with organization- and session-level controls.
Cloudflare introduced WriteGuard, a private beta security layer for MCP servers that intercepts requests, enforces tool-specific policies, and records blocked or failed actions for auditing. The product is designed to reduce risks from AI agents using write-capable access to external tools and services through MCP.
ElevenLabs released an open-source MCP server for Claude Desktop, Cursor, and other MCP clients. The locally run server used an ElevenLabs API key and supported speech generation, voice cloning, and audio transcription.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourcethenewstack.io
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.