Cover story
MCP security
Cantina threat advisory: how Anthropic's MCP stdio model turns configuration into code execution
Analysis of how untrusted input reaching MCP stdio configuration can enable local code execution attacks.
· Cantina
Cantina editorial
April 2026 70 stories
Intelligence for the new security frontier
Analysis, perspectives, and field notes from the people building and operating Cantina.
Latest storiesDispatches
Analysis / Field notes / News
AI governance
05Framework for assessing AI agent governance readiness across inventory, permissions, approvals, logging, and incident response.
Cantina
application security
06Automated code analysis helps teams counter "vibe coding" risks from AI-assisted development by catching security flaws early and reducing alert fatigue.
Cantina
AI Act
07SaaS teams must prepare now for EU AI Act transparency obligations taking effect August 2, 2026.
Cantina
MCP security
08A security framework for governing Model Context Protocol access to prevent costly AI agent mistakes
Cantina
GitHub Actions
09Analysis of the tj-actions/changed-files compromise that exposed secrets through mutable GitHub Action tags in 23,000+ repositories.
Cantina
compliance
10Manual compliance evidence collection creates operational friction; continuous automated compliance reduces audit timelines and engineering overhead.
Cantina
Security
11Spring AI's SimpleVectorStore is vulnerable to remote code execution through SpEL injection in filter expressions when keys are not properly sanitized.
Cantina
cybersecurity
12Enterprises managing 45-83 security tools face fragmentation, alert fatigue, and financial losses that agentic AI platforms can resolve.
Cantina
Page 5 of 6 · 70 stories