MCP Servers Are Ready-Made Exfil Kits
Reco found 62% of 500 public MCP servers combine local files and internet reach. Break the shell-files-egress triple before prompt injection becomes OS access.
7 articles
Reco found 62% of 500 public MCP servers combine local files and internet reach. Break the shell-files-egress triple before prompt injection becomes OS access.
InjecMEM shows one prompt can plant lasting instructions in AI agent memory. Details on the attack, 76% ASR results, and how to harden memory systems.
Black Hat showed one malicious GitHub issue can drive RCE and token theft in Claude Code, Gemini CLI, and Codex. Architectural fixes for agent harnesses.
Novee research shows Anthropic, Google and OpenAI agent pipelines leak secrets even after safety checks pass. The failure is composed trust across stages.
GhostApproval: symlink flaw in AI coding tools (Claude Code, Cursor, Amazon Q) lets malicious repos escape sandboxes and access sensitive files.
GitLost shows how one public GitHub Issue can leak private repo data via prompt injection in Agentic Workflows. Key lessons for securing agentic systems.
Dual-firewall and adaptive out-of-band defense patterns for securing agentic and RAG systems against prompt injection.