cd/entity/Deadbugz· home› entities› Deadbugz
grep -l @deadbugz /news/*.json | wc -l → 5

Deadbugz

mentions 5 type Organization feed RSS

// recent coverage 5 mentions

16:56
2026-09-22
dev.to
ai-agents

MCP Tool Poisoning: A Name Allowlist Is Not Enough

A developer built a four-container demo showing that deny-by-default tool-name allowlists fail to stop MCP tool poisoning, because an MCP server can rewrite its own tool descriptions mid-session after…

10:16
2026-09-12
byteiota.com
ai-safety

Deadbugz: The MCP Attack That Waits 3 Calls Before Striking

Pillar Security researchers traced an active MCP supply-chain campaign called Deadbugz to a single GitHub account, `zellkernel`, which filed 23 pull requests across unrelated AI, MCP, and developer-to…

16:31
2026-09-09
omnafy.com
ai-safety

Deadbugz: A new kind of malicious MCP server

Pillar Security documented Deadbugz, a malicious MCP server attributed to GitHub account zellkernel, which targeted 23 GitHub repositories in one evening and breached none. The server evades detection…

05:09
2026-09-08
byteiota.com
ai-safety

MCP Servers Are Being Weaponized — Here’s the Proof

A supply-chain attack dubbed Deadbugz hit 23 Model Context Protocol (MCP) projects in 74 minutes, according to a new audit that also found 91.8% of production MCP servers have no authentication. The a…

11:29
2026-08-12
pillar.security
ai-safety

Deadbugz: Currently Active MCP Supply-Chain Campaign

Pillar Security researchers identified an active campaign, dubbed Deadbugz, that distributes a malicious Model Context Protocol (MCP) server named 'productivity-suite' via 23 GitHub pull requests from…

// co-occurs with top 8 entities
// topics top 6 topics