Skip to content
Wednesday 2026-09-16 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • Smart Home Security Debt: When Your Router Becomes the Agent’s Attack Surface

    The smart home hub sitting on your counter is marketed as a seamless command center for your life, promising to manage lights, locks, and climate with a simple voice prompt. It feels like a leap into the future, but that polished interface hides a crumbling foundation. August 2026 has been a brutal month for the…

  • MCP Security

    MCP Security is the discipline of identifying, mitigating, and managing the risks created by the Model Context Protocol — the open standard that connects AI agents to external tools, data sources, and APIs.

  • SEC Custody Rule Enters Final Review. Combined With Four Other Regulatory Tracks, the Institutional Stack Is Nearly Complete.

    The Securities and Exchange Commission’s custody modernization rule (RIN 3235-AN46) entered Office of Information and Regulatory Affairs review on August 25, marking the final procedural step before the Commission publishes a notice of proposed rulemaking. The NPRM is targeted for October 2026. On its own, this is a significant but incremental development. Viewed alongside four…

  • Coinbase’s Tokenized Stocks Are Live on Base. The SEC’s Framework Isn’t.

    Coinbase has launched tokenized U.S. equities on the Base blockchain. The August 24 rollout includes 13 stocks — NVDAc, METAc, AAPLc, GOOGLc, AMZN, COIN, CRCL, INTC, MSFT, MSTR, SNDK, SPCX, and TSLA — each representing a direct claim on the underlying share, not a synthetic derivative. The product is live. The U.S. regulatory framework that…

  • CVE-2026-76404: The MCP Security Wave Reaches Enterprise Infrastructure

    The security landscape for the Model Context Protocol (MCP) has reached a critical inflection point with the disclosure of CVE-2026-76404. This is the first critical vulnerability identified in a vendor-backed, enterprise-grade MCP server product, marking a departure from the experimental frameworks and open-source tools that have dominated the protocol’s early history. According to the official…

  • The SEC Is Writing Its Own Crypto Law. Congress Didn’t Ask It To.

    The Securities and Exchange Commission (SEC) has a peculiar way of signaling that the era of regulation-by-enforcement is nearing its expiration date. On August 18, 2026, the agency bypassed its own public meeting schedule, opting instead for a seriatim vote to release Regulation Crypto Assets (Release No. 33-11434). It was a quiet, surprise maneuver that…

  • The Agent Harness Emerges as the New Security Frontier

    Something broke in how we think about agent security. The recent disclosure of CVE-2026-18830 in the Amazon Bedrock AgentCore harness does not just patch a bug — it reveals a structural vulnerability class that the industry has not yet adequately named. The vulnerability is straightforward in concept but significant in implication. CVE-2026-18830 (CVSS v4.0: 8.6)…

  • The Model Context Protocol Reaches a Security Inflection Point

    The Seoul Inflection Point More than 21,000 internet-facing MCP server instances are currently exposed, with nearly 92% of audited production servers lacking basic OAuth authentication. This data, surfacing alongside a growing catalog of critical CVEs and the formalization of the OWASP MCP Top 10, has transformed the Model Context Protocol (MCP) Dev Summit in Seoul…