Skip to content
Monday 2026-09-14 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • SEC Custody Rule Enters Final Review. Combined With Four Other Regulatory Tracks, the Institutional Stack Is Nearly Complete.

    The Securities and Exchange Commission’s custody modernization rule (RIN 3235-AN46) entered Office of Information and Regulatory Affairs review on August 25, marking the final procedural step before the Commission publishes a notice of proposed rulemaking. The NPRM is targeted for October 2026. On its own, this is a significant but incremental development. Viewed alongside four…

  • Coinbase’s Tokenized Stocks Are Live on Base. The SEC’s Framework Isn’t.

    Coinbase has launched tokenized U.S. equities on the Base blockchain. The August 24 rollout includes 13 stocks — NVDAc, METAc, AAPLc, GOOGLc, AMZN, COIN, CRCL, INTC, MSFT, MSTR, SNDK, SPCX, and TSLA — each representing a direct claim on the underlying share, not a synthetic derivative. The product is live. The U.S. regulatory framework that…

  • CVE-2026-76404: The MCP Security Wave Reaches Enterprise Infrastructure

    The security landscape for the Model Context Protocol (MCP) has reached a critical inflection point with the disclosure of CVE-2026-76404. This is the first critical vulnerability identified in a vendor-backed, enterprise-grade MCP server product, marking a departure from the experimental frameworks and open-source tools that have dominated the protocol’s early history. According to the official…

  • The SEC Is Writing Its Own Crypto Law. Congress Didn’t Ask It To.

    The Securities and Exchange Commission (SEC) has a peculiar way of signaling that the era of regulation-by-enforcement is nearing its expiration date. On August 18, 2026, the agency bypassed its own public meeting schedule, opting instead for a seriatim vote to release Regulation Crypto Assets (Release No. 33-11434). It was a quiet, surprise maneuver that…

  • The Agent Harness Emerges as the New Security Frontier

    Something broke in how we think about agent security. The recent disclosure of CVE-2026-18830 in the Amazon Bedrock AgentCore harness does not just patch a bug — it reveals a structural vulnerability class that the industry has not yet adequately named. The vulnerability is straightforward in concept but significant in implication. CVE-2026-18830 (CVSS v4.0: 8.6)…

  • The Model Context Protocol Reaches a Security Inflection Point

    The Seoul Inflection Point More than 21,000 internet-facing MCP server instances are currently exposed, with nearly 92% of audited production servers lacking basic OAuth authentication. This data, surfacing alongside a growing catalog of critical CVEs and the formalization of the OWASP MCP Top 10, has transformed the Model Context Protocol (MCP) Dev Summit in Seoul…

  • CLARITY Act Section 404: The 360-Day Rulemaking That Defines Stablecoin Competition

    The Senate is in recess, the cloture vote is scheduled for September 15, and prediction markets price the CLARITY Act’s passage at roughly 15%. But the question that matters for stablecoin builders and investors is not whether the bill clears the floor — it is what happens in the 360-day rulemaking window that follows enactment.…

  • The Structural Cost of the MCP Security Crisis

    By early August 2026, the Model Context Protocol ecosystem hit a number that stops being a trend and starts being a structural condition: over 40 disclosed CVEs affecting implementations, with approximately 15,930 active public servers across four major registries. A ZDI scan of 19,000 MCP servers found that between 600 and 1,650 are exploitable based…