5 articles with this tag
GhostSplice: Multi-Tool Payload Assembly in MCP Agents
Inside GhostSplice (August 2026): how malicious MCP tools split instructions across turns to bypass single-prompt guardrails and exfiltrate developer secrets.
The CTF Escape Horizon: AI Agent Model Breakouts Explained
An analysis of the July 2026 OpenAI and Anthropic sandbox escapes, zero-day Artifactory exploits, misconfigured evals, and microVM isolation.
The Confused Deputy in AI Tooling: Unscoped Keys in Agent Workspaces
How autonomous AI agents with unscoped API keys and excessive tool privileges create confused deputy vulnerabilities in modern developer IDEs and workflows.
The AI-Generated Code Security Wake‑Up Call: Symbiotic Security’s $10M and the New AppSec Reality
Symbiotic Security raised $10M to secure AI-generated code, a signal that the industry is waking up to what high-velocity AI development actually ships.
The MCP Git Wake-Up Call: Why Your Agentic Workflow Is an Attack Surface
Three critical vulnerabilities in Anthropic's MCP Git server expose a new attack class: indirect prompt injection through tool servers.