Good evening. Here is what matters in AI today, and how to put it to work.
AI's energy appetite is becoming a genuine infrastructure risk, while a cluster of unpatched MCP vulnerabilities demands immediate action from any team running agent tooling.
~3 min read · last 12 hours
In today's issue
01
US data centers could burn more natural gas than Germany and Japan combined by 2035
02
The AI data center boom is colliding with cities scarred by big industry
03
Amazon Bedrock prompt caching can cut input token costs by up to 90%
04
Gemini 3.8 Live and 3.8 Live Extended Thinking launch
05
Critical SSRF in @zereight/mcp-gitlab allows credential theft via header injection
Main story
US data centers could burn more natural gas than Germany and Japan combined by 2035
A new analysis projects that the AI-driven data center expansion could make the US one of the world's largest natural gas consumers within a decade.
Why it matters: Energy exposure is now a board-level risk for any company with large-scale AI infrastructure: factor it into your multi-year cost and sustainability planning now, not after capacity contracts are signed.
What to watch next: Watch for utility and regulatory responses: if state or federal energy regulators begin imposing caps or surcharges on data center gas consumption, the economics of large-scale AI infrastructure will shift quickly and force a faster pivot to efficiency and renewables.
We are seeing a clear through-line today: the compute buildout powering AI is hitting hard limits in energy, community tolerance, and economics, while new tools on the cost side show teams can already claw back significant spend if they optimize smartly.
Agentic AI vs LLMs: Why an Agent Doesn't Stop at the Answer
Stanford Online
Flow matching for Beginners | @ariG23498
Hugging Face
The Signal
Today's items collectively signal that the AI buildout is entering a phase where physical and financial constraints are as important as model capability. Energy demand projections and community opposition to data center siting are no longer background noise: they are shaping where and how compute gets built. At the same time, the agent ecosystem is maturing fast, but security is lagging, and the MCP vulnerabilities disclosed today show that organizations adopting agent-based workflows need a security review cadence that matches their deployment pace.
All the best, the KYFEX team
Quick hits
AI infrastructure: cost, scale, and the energy reckoning
The AI data center boom is colliding with cities scarred by big industry
Community opposition to data center siting is intensifying, with Philadelphia the latest city where officials proposed building on a site already damaged by an oil refinery.
Why it matters: Permitting and community relations are becoming genuine project-delay risks, not just PR considerations, for teams planning new compute capacity.
Amazon Bedrock prompt caching can cut input token costs by up to 90%
Prompt caching in Amazon Bedrock, applied across six practical scenarios using the Converse API, can slash input token costs dramatically when the same context is sent repeatedly to foundation models.
Why it matters: For any production workload with stable system prompts or repeated context, implementing caching today is one of the highest-ROI infrastructure moves available.
Agents are shipping fast, from Meta opening WhatsApp Business setup to AI coding tools, to Google releasing live extended-thinking models, but a cluster of critical vulnerabilities in the MCP ecosystem is a sharp reminder that agent infrastructure is still maturing in ways that matter for security teams.
Gemini 3.8 Live and 3.8 Live Extended Thinking launch
Google has released Gemini 3.8 Live and a companion Extended Thinking variant, adding real-time multimodal and reasoning capabilities to its model lineup.
Why it matters: Extended thinking in a live, real-time model is a meaningful capability step for agent pipelines that need to reason over streaming inputs.
Critical SSRF in @zereight/mcp-gitlab allows credential theft via header injection
All versions of the popular mcp-gitlab package are vulnerable to server-side request forgery through a manipulated X-GitLab-API-URL header, and no patch exists yet.
Why it matters: Any team running this MCP server should treat it as compromised until a patch ships: an attacker can steal GitLab credentials through a simple header manipulation.
Build real-world applications from the command line using Gemini CLI, Google's open-source agentic coding assistant that coordinates local tools and cloud services to automate coding and creative...
You are a security engineer reviewing an MCP (Model Context Protocol) server integration. Analyze the following code or configuration and identify: 1) Any missing Host or Origin allowlist checks on HTTP endpoints, 2) Any inputs that are passed to downstream HTTP requests without validation (potential SSRF), 3) Any unauthenticated transports or endpoints, 4) Any places where attacker-controlled headers could redirect requests. For each finding, state the risk in plain language and suggest a concrete fix. Code to review: [PASTE YOUR MCP SERVER CODE HERE]
Why it helps: With multiple critical unpatched vulnerabilities disclosed today in a widely used MCP package, running this audit on your own MCP integrations is a fast way to catch the same classes of flaw before they are exploited.
Before you ship it
The risk
Unpatched MCP server vulnerabilities disclosed today can allow credential theft and unauthenticated command execution, and because MCP servers often run with elevated access to internal systems, a single compromised integration can cascade across an entire agent pipeline.
Do this
Inventory every MCP server your agents connect to, check each against today's advisories, and disable or network-isolate any that cannot be immediately patched, applying a Host and Origin allowlist as a minimum compensating control.
Ready to ship AI, not just read about it?
KYFEX designs and builds production AI for teams that need it working, not just demoed. Tell us what you're working on and we'll bring the engineering.