
TRC analysis shows attackers exploiting MCP Python SDK flaw (CVE-2024-45590) to steal OAuth credentials by redirecting AI app authentication flows to malicious servers. Stolen tokens enabled lateral movement across connected cloud services and APIs. Runtime segmentation helps contain such post-compromise activity. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/mcp-python-sdk-oauth-credential-theft-2026
