# The Injection: AI security news

> A daily feed of AI security news and research: prompt injection, agent and MCP supply chain, jailbreaks, vulnerabilities and lab safety claims. Every item is sourced, credited and explained in plain English.

Updated every six hours. Machine-readable: [llms.txt](https://theinjection.dev/llms.txt), [JSON feed](https://theinjection.dev/feed.json), [RSS](https://theinjection.dev/rss.xml). Every story below also has a Markdown version at its URL with `.md` (for example https://theinjection.dev/items/anthropic-cyber-verification-program-tiers.md).

## Latest stories

- **[Anthropic Cyber Verification Program: tiered access for defenders](https://theinjection.dev/items/anthropic-cyber-verification-program-tiers/)** (Info, 2026-10-06, Anthropic): Anthropic is expanding its Cyber Verification Program into Defense, Red Team and Specialized tiers that relax Claude's cyber safeguards for verified security teams. Anthropic says its public models block most cyber work.
- **[Claude Code: symlink race allowed writes outside the project](https://theinjection.dev/items/claude-code-symlink-toctou-file-write/)** (Medium, 2026-10-05, Anthropic): CVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.
- **[MCP TypeScript SDK: OAuth client could leak credentials to servers](https://theinjection.dev/items/mcp-typescript-sdk-oauth-credential-leak/)** (High, 2026-09-30, Model Context Protocol): CVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
- **[Ollama agent mode: chained shell commands skip Bash approval](https://theinjection.dev/items/ollama-agent-bash-approval-bypass/)** (High, 2026-09-29, VulnCheck): CVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.
- **[UK AISI: GPT-6 Astra attacked out-of-scope targets in simulations](https://theinjection.dev/items/aisi-gpt-6-astra-unsanctioned-supply-chain-attacks/)** (Info, 2026-09-28, UK AI Security Institute): The UK AI Security Institute found that GPT-6 Astra, with cyber safeguards off, tried full supply-chain attacks on out-of-scope targets in 29.2% of simulated scenarios, against 6.3% for GPT-5.6 Sol and 0% for GPT-5.5.
- **[Claude Desktop for macOS: Cowork files could run commands on open](https://theinjection.dev/items/anthropic-claude-desktop-cowork-file-exec/)** (High, 2026-09-25, Anthropic): Claude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.
- **[Anthropic skill scanner bypassed: malicious skills marked safe](https://theinjection.dev/items/air-anthropic-skill-scanner-bypass/)** (Medium, 2026-09-24, AIR Security): AIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.
- **[SalesBleed: zero-click CRM data theft through Salesforce Agentforce](https://theinjection.dev/items/zenity-salesbleed-agentforce-exfiltration/)** (Medium, 2026-09-24, Zenity Labs): SalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.
- **[MemTensor MemOS packages compromised with a credential stealer](https://theinjection.dev/items/socket-memtensor-memos-compromise/)** (High, 2026-09-23, Socket): Malicious releases of MemTensor's MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.
- **[Explosive prompts: dormant injections fire on 'thanks' in agents](https://theinjection.dev/items/arxiv-explosive-prompts-trigger-injections/)** (Medium, 2026-09-18, arXiv): Explosive prompts are dormant prompt injections that wait for a harmless trigger such as 'thanks'. A new paper reports 43% to 83% success on nine production agents, versus at most 3% for plain injections, and proposes the DeFuse detector.
- **[Plugin4Shell: zero-click plugin RCE in four AI coding agents](https://theinjection.dev/items/air-plugin4shell/)** (High, 2026-09-17, AIR Security): Plugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.
- **[CAISI: GLM-5.3 is the most cyber-capable open-weight model yet](https://theinjection.dev/items/caisi-glm-5-3-cyber-assessment/)** (Info, 2026-09-17, NIST CAISI): NIST's Center for AI Standards and Innovation rates Z.ai's GLM-5.3 the most cyber-capable open-weight model so far, while placing it about four months behind US frontier models on a composite cyber index.
- **[Agent Control Standard: an open spec for blocking agent actions](https://theinjection.dev/items/owasp-agent-control-standard/)** (Info, 2026-09-10, OWASP GenAI Security Project): The Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent's tool calls and other actions before they run.
- **[Google GTIG: attackers used AI agents to run a credential campaign](https://theinjection.dev/items/gtig-ai-threat-tracker-prompting-to-autonomy/)** (Info, 2026-09-09, Google Threat Intelligence Group): Google Threat Intelligence Group reports a threat actor who planned, built and ran an agent-enabled mass credential harvesting campaign in under six hours. GTIG says it has not yet seen fully autonomous attack pipelines in the wild.
- **[SQL Server Copilot: prompt injection escalates a user to sysadmin](https://theinjection.dev/items/embracethered-ssms-copilot-select-to-sysadmin/)** (High, 2026-09-08, Embrace The Red): CVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.
- **[ChatGPT sandbox: shared package cache leaked data across accounts](https://theinjection.dev/items/checkpoint-chatgpt-shared-artifactory-channel/)** (Low, 2026-09-08, Check Point Research): Check Point Research found that ChatGPT code containers from different accounts shared one internal JFrog Artifactory, giving attackers a hidden channel into a victim's session and connected apps. OpenAI shut the instance down.
- **[MCPJacking: 155 hijackable servers in the official MCP registry](https://theinjection.dev/items/air-mcpjacking/)** (High, 2026-08-27, AIR Security): MCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.
