· artificial intelligence · 4 min read
AI and cloud briefing: MCP goes enterprise-ready, a wormable Windows DNS flaw, and hyperscalers' record cloud quarter
The Model Context Protocol's stateless core has landed in Amazon Bedrock AgentCore. Microsoft patched a critical, unauthenticated Windows DNS Server flaw that is wormable. And Azure, AWS and Google Cloud all posted accelerating growth, with AWS and Google Cloud launching a joint multicloud collaboration.

Here is our latest round-up of what’s changing in AI and cloud for UK businesses, with links to the original sources so you can read further.
Lead story: Model Context Protocol’s stateless spec lands in Amazon Bedrock AgentCore
The Model Context Protocol (MCP), the open standard that governs how AI agents connect to business systems, finalised its 2026-07-28 specification, the largest revision since launch. The update replaces the old session-based design with a stateless core that runs on ordinary HTTP infrastructure, adds extensions for server-rendered UIs and long-running tasks, and makes the Enterprise-Managed Authorization extension stable. That extension lets organisations centrally manage authorization for MCP servers, so end users sign in once to reach every connected server. Amazon has already built the stateless core into Bedrock AgentCore, letting developers deploy MCP servers without managing sessions or persistent connections. More detail is available from the Model Context Protocol blog and Google’s developer blog on scaling agent infrastructure.

Why this matters: if your business connects AI agents to internal systems, this update removes a lot of the plumbing work around session state and access control. The stable authorization extension in particular is worth a look if you are managing multiple MCP servers and want one login for staff instead of several.
Cyber security: critical, wormable Windows DNS Server flaw, no login required
Microsoft’s August Patch Tuesday fixed CVE-2026-62878, a critical remote code execution flaw in Windows DNS Server, rated 9.8 out of 10 on the CVSS scale. It is a stack-based buffer overflow that a remote, unauthenticated attacker can trigger with a specially crafted network packet, no credentials or user interaction needed. Researchers describe it as wormable, meaning it could spread automatically between vulnerable servers. It affects Windows Server releases from 2012 through 2025. Microsoft patched it on 11 August 2026, alongside more than 400 other fixes that month. Further technical detail is available from SecurityWeek and the Zero Day Initiative’s August review.

Why this matters: DNS servers sit at the centre of most networks, and domain controllers often run DNS too. If you have not applied August’s updates yet, this patch should move to the top of the list, particularly on any internet-facing or domain-controller DNS role. Given the wormable nature of the flaw, treat this as an urgent patch rather than routine monthly maintenance.
Cloud: Azure, AWS and Google Cloud all post accelerating growth
Second-quarter 2026 results show all three major cloud platforms converting AI infrastructure spending into faster cloud revenue growth. Microsoft Azure grew 43% year on year and crossed $100 billion in quarterly revenue for the first time, with Microsoft 365 Copilot passing 30 million paid seats. AWS reported $37.6 billion in cloud revenue for the quarter. Google Cloud revenue reached $20.03 billion, up 63% year on year, even after Google cut compute pricing by 8% across all regions earlier in the year. Separately, AWS and Google Cloud launched a joint multicloud collaboration to simplify connecting the two platforms, with Microsoft Azure expected to join later in 2026. Coverage is available from CIO Dive and Network World.

Why this matters: the growth numbers confirm cloud spending on AI workloads is translating into real revenue for providers, which tends to mean continued investment in capacity and features rather than a slowdown. The AWS-Google multicloud link-up is also worth watching if you run workloads across more than one provider, since it points toward easier interoperability between platforms that have historically been kept separate.
The takeaway
This briefing’s stories point the same way: agent infrastructure is maturing with enterprise-grade authorization and simpler deployment, security teams need to treat this month’s DNS patch as urgent rather than routine, and the major cloud platforms are all growing faster off the back of AI demand. If you are building or connecting AI agents, the new MCP authorization extension is worth evaluating for centralising access control. If you run Windows DNS Server anywhere in your estate, check that August’s patch is applied. And if you operate across more than one cloud provider, keep an eye on how the AWS-Google multicloud collaboration develops. We can help you assess what these changes mean for your infrastructure and security posture. Get in touch.
AI Agent based research and content, AI can do mistake, please help us to improve.