What is new in Cyron, September 2026
Cyron AI Security arrives, MCP and A2A traffic is recognised in every edition, and attacks on WebSocket, gRPC and streams now trigger a block.
The September 2026 release adds Cyron AI Security, recognises AI-agent traffic in every edition, and extends blocking to streaming protocols. Here is everything that changed, and which edition each change applies to.
Every change, and which edition gets it
| Change | SaaS | On-Premise |
|---|---|---|
| MCP and A2A traffic recognised and labelled, with filters and badges in the live view | Yes | Yes |
| API-layer rules applied to MCP traffic; ordinary MCP calls recognised cleanly, with no false alerts | Yes | Yes |
| Attacks on WebSocket, gRPC, Server-Sent Events and Socket.IO now trigger a block of the source | Yes | Yes |
| Cyron AI Security, with seven agent incident types | Comes with Cyron On-Premise | Yes |
| Database changes applied automatically on upgrade | Handled for you | Yes |
| iris recognises agent traffic and captures Server-Sent Events | Yes | Yes |
MCP and A2A traffic, recognised and labelled. AI agents reach their tools over the Model Context Protocol (MCP) and reach each other over the Agent-to-Agent protocol (A2A). Both are open standards, set out in the MCP specification and the A2A specification. Cyron now recognises both in every edition. The live view marks agent traffic with badges, and new filters let you isolate it. You can see where agent traffic runs before you decide how to protect it.
API-layer rules for MCP. Cyron API Security now applies its API-layer rules to MCP traffic, so MCP is protected at the API layer, like the rest of your APIs. Ordinary MCP calls are recognised cleanly, with no false alerts.
Blocks on streaming protocols. Attacks on WebSocket, gRPC, Server-Sent Events and Socket.IO now trigger a block of the source, as HTTP attacks always have. The 31 real-time detectors for streaming and RPC APIs find these attacks as they arrive. Now a confirmed attack on a stream ends the same way as one on REST: a cryptographically signed block command to the agent that enforces it. Detection still runs out of band on a copy of your traffic, so the block adds nothing to your request path.
Cyron AI Security. The new product is agent boundary protection for MCP and A2A. Cyron AI Security inspects tool lists, tool calls, tool responses and agent-to-agent messages with 15 agent-layer detectors. It blocks the threat classes and severity you choose. Each finding is classified to the OWASP Top 10 for LLM Applications (2025) or the OWASP Top 10 for Agentic Applications (2026). It runs fully air-gapped, with no call-home and no GPU, either as a gateway in front of your MCP and A2A servers or inside Cyron On-Premise. Inside Cyron On-Premise, its detections arrive as seven agent incident types, in the same dashboard and SIEM feed as your API incidents. In SaaS, Cyron recognises and labels MCP and A2A traffic and protects MCP at the API layer. Agent-layer analysis comes with Cyron AI Security, included with Cyron On-Premise.
Automatic database changes on upgrade. On-premise upgrades now apply database changes automatically and keep your data. There is no manual migration step to schedule. In SaaS, this is handled for you.
iris sees agents and Server-Sent Events. iris, the eBPF kernel agent, now recognises agent traffic and captures Server-Sent Events. It joins REST, WebSocket, gRPC and Socket.IO, so all five API protocols, plus MCP and A2A, can be captured from the kernel with no code changes.
What do you need to do after the September 2026 release?
In SaaS, nothing. Every SaaS change above is already live in your account.
On-premise, run the in-place upgrade. It keeps your data and applies the database changes automatically.
Then look at what you have. Filter the live view for MCP and A2A traffic. Every MCP exchange you find there is protected at the API layer from today.
To use the new blocks on stream protocols, blocking runs through an agent that can block: iris, the Linux proxy agent or the web-server module. Save the blocking address in Settings, and confirmed attacks on WebSocket, gRPC, Server-Sent Events and Socket.IO will trigger a block of the source.
To evaluate Cyron AI Security, tell us which MCP servers and agents you run. We will set up an evaluation on your own servers.
Where to read more
Every release, newest first, is in the Cyron changelog. The previous release post is the March 2026 release.
New to Cyron? Judge the API engine before you talk to us. The free plan analyses five requests a minute on every protocol, with no card and no time limit.
Start free · Running AI agents with tool access? See Cyron On-Premise.