AI Security Weekly
Issue #12 — June 2026
The Principal-Agent Question Reaches the Cyber Form
Flowise CVE-2026-40933 (1-click stdio MCP RCE) and LibreChat CVE-2026-44653 (MCP secret exposure, fixed in 0.8.4) turn the named-insured question from a thought experiment into a claims question. The connector substrate that delegates agent authority is now the substrate adversaries are targeting — and current cyber and E&O forms were drafted before any of those words meant what they now mean.
Runtime Containment as Underwriting Evidence
Microsoft Build 2026 published Execution Container SDK, Foundry runtime DLP, and Defender AI model scanning in coordinated rollout. Together they produce the audit substrate an underwriter can score against and a regulator can read as conformity evidence — the first runtime stack designed for cross-audience evidence. Anthropic’s CVD dashboard at 1,596 vulns / 281 projects is now part of the supply-side file.
Five Moves Before the Underwriter Asks
The Article 50 consultation closed June 3 with eight weeks to the August 2 effective date. What every high-risk deployer should be doing now: inventory MCP connectors, containerize agent execution, treat model-provider CVD as supply-side file, close the Article 50 implementation loop, and document the principal-agent chain. Market Index W23: 37.7 (flat against W21).