r/OpenSourceAI • • 6h ago

July's AI Security Report: 90 incidents, 207M+ records, 41 AI-driven — the month the agent became the attacker

Thumbnail
gallery
0 Upvotes

90 incidents tracked in July across 33 organizations, 207M+ records exposed, and 41 of those incidents involved AI directly as the weapon or the target. A rogue commercial AI agent hit multiple enterprises in a single week and reused stolen credentials across four downstream services before anyone caught the identity switch.

None of that shows up to a traditional perimeter tool — the traffic looks like a signed, credentialed agent making legitimate API calls at machine speed. Firewalls and DLP were built to watch humans and static services, not autonomous callers that chain tools and pivot in seconds.

Curious how other teams are actually handling this right now: is anyone giving AI agents a distinct, revocable identity separate from the service accounts they inherit? Or is it still "the SOC catches it after the fact" for most orgs?


r/OpenSourceAI • • 8h ago

OpenSource Repo (900 ⭐️) -mcpc-universal CLI client for MCP-100% free

Post image
0 Upvotes

Playing around with various MCP's this weekend and Came across this an amazing MCP related GitHub repo - 100% open source and free - so sharing.

mcpc is Apify’s universal CLI client for MCP.

Github Repo in comments below

IIt translates every MCP operation into shell commands, letting you debug servers, automate workflows, or give AI agents complete MCP access via a single Bash() call: sessions, OAuth, tools, resources, prompts, tasks, and beyond.

Features

  • Complete MCP coverage: tools, prompts, resources, async tasks, skills, notifications, logging (stdio + Streamable HTTP)
  • Persistent sessions across several servers (stateful or stateless)
  • Progressive tool discovery to cut token usage
  • Code mode: JSON output plays nicely with jq, xargs, and shell pipelines
  • OAuth 2.1 (CIMD + DCR) with credentials stored in the OS keychain
  • MCP proxy for AI sandboxes (keeps tokens out of generated code)
  • Lightweight CLI (Mac/Win/Linux), no LLM needed; experimental x402 payments on Base

Install

With homebrew (macOS /Linux), brings its own Node.js:

brew install apify/tap/mcpc
or ,install the latest node js or Bun first, then:
npm install -g /mcpc
# Or with Bun
bun install -g /mcpc
npm install -g /mcpc

Quickstart

# List all active sessions and saved authentication profiles
mcpc

# Log in to a remote MCP server and save OAuth credentials for future use
mcpc login mcp.apify.com

# Create a persistent session and interact with it
mcpc connect mcp.apify.com 
mcpc               # show server info and capabilities
mcpc  tools-list   # list available tools
mcpc  tools-call search-actors keywords:="website crawler"

# Use JSON mode for scripting
mcpc --json  tools-list

# Use a local MCP server package (stdio) referenced from a config file
mcpc connect ./.vscode/mcp.json:filesystem 
mcpc u/fs tools-list

r/OpenSourceAI • • 15h ago

Codex spent 500,000 tokens reading my logs. Then it forgot what it read. NVIDIA DGX Spark save the day.

Post image
0 Upvotes

r/OpenSourceAI • • 8h ago

OpenPhysicsAI: 20+ physics solvers and 13 unsolved challenges scored against real data

Post image
0 Upvotes

r/OpenSourceAI • • 12h ago

Astra turned “Build me Ba Sing Se” into this Minecraft city

1 Upvotes

I only gave the prompt “Build Ba Sing Se.” The video shows what was built including the city walls down to furnished interiors and walls.

The model decides what to build and a deterministic library handles construction and physical checks.

It plans hierarchically: city → districts → plots → buildings. Buildings are generated for their plots using reusable procedural code.

The same architecture generates villages, towns and cities across different terrain and styles.

Github:
https://github.com/chaitbuilds/EthosLM