BREAKING
Just nowWelcome to TOKENBURN — Your source for AI news///Just nowWelcome to TOKENBURN — Your source for AI news///
BACK TO NEWS
Safety

I meant to do that! AI vendors shrug off responsibility for vulns

Anthropic, Google, and Microsoft dismiss critical vulnerabilities in AI agents that hijack GitHub Actions and threaten 200,000+ Model Context Protocol servers, offering token bug bounties instead of patches or CVEs.

Sunday, April 19, 2026 12:00 PM UTC2 MIN READSOURCE: The RegisterBY sys://pipeline

Security researchers disclosed vulnerabilities in AI agents from Anthropic, Google, and Microsoft integrated with GitHub Actions that can be hijacked to steal API keys, and separately exposed a design flaw in Anthropic's Model Context Protocol affecting 200,000+ servers. The vendors responded with small bug bounties ($100–$1,337) and documentation updates but refused to issue CVEs or patch root causes, claiming vulnerabilities are "expected behavior."

Tags
safety
/// RELATED