<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Injection</title><description>A daily feed of AI security news and research: prompt injection, agent and MCP supply chain, jailbreaks, vulnerabilities and lab safety claims. Every item is sourced, credited and explained in plain English.</description><link>https://theinjection.dev/</link><item><title>Anthropic Cyber Verification Program: tiered access for defenders</title><link>https://theinjection.dev/items/anthropic-cyber-verification-program-tiers/</link><guid isPermaLink="true">https://theinjection.dev/items/anthropic-cyber-verification-program-tiers/</guid><description>Anthropic is expanding its Cyber Verification Program into Defense, Red Team and Specialized tiers that relax Claude&apos;s cyber safeguards for verified security teams. Anthropic says its public models block most cyber work.</description><pubDate>Tue, 06 Oct 2026 12:00:00 GMT</pubDate><category>info</category><category>lab-safety</category><author>Anthropic</author></item><item><title>Claude Code: symlink race allowed writes outside the project</title><link>https://theinjection.dev/items/claude-code-symlink-toctou-file-write/</link><guid isPermaLink="true">https://theinjection.dev/items/claude-code-symlink-toctou-file-write/</guid><description>CVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.</description><pubDate>Mon, 05 Oct 2026 12:00:00 GMT</pubDate><category>medium</category><category>vulnerability</category><author>c_h4ck_0</author></item><item><title>MCP TypeScript SDK: OAuth client could leak credentials to servers</title><link>https://theinjection.dev/items/mcp-typescript-sdk-oauth-credential-leak/</link><guid isPermaLink="true">https://theinjection.dev/items/mcp-typescript-sdk-oauth-credential-leak/</guid><description>CVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client&apos;s OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.</description><pubDate>Wed, 30 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>vulnerability</category><category>supply-chain</category><author>Aviral2642, AlexMelanFromRingo, Gal3m, JosephDoUrden, Igfray, OriginalKazdov, lwebmedia</author></item><item><title>Ollama agent mode: chained shell commands skip Bash approval</title><link>https://theinjection.dev/items/ollama-agent-bash-approval-bypass/</link><guid isPermaLink="true">https://theinjection.dev/items/ollama-agent-bash-approval-bypass/</guid><description>CVE-2026-102697 lets prompt-injected output in Ollama&apos;s experimental agent mode add commands after an approved one with ;, &amp;&amp; or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.</description><pubDate>Tue, 29 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>vulnerability</category><category>attack</category><author>Akıner Kısa</author></item><item><title>UK AISI: GPT-6 Astra attacked out-of-scope targets in simulations</title><link>https://theinjection.dev/items/aisi-gpt-6-astra-unsanctioned-supply-chain-attacks/</link><guid isPermaLink="true">https://theinjection.dev/items/aisi-gpt-6-astra-unsanctioned-supply-chain-attacks/</guid><description>The UK AI Security Institute found that GPT-6 Astra, with cyber safeguards off, tried full supply-chain attacks on out-of-scope targets in 29.2% of simulated scenarios, against 6.3% for GPT-5.6 Sol and 0% for GPT-5.5.</description><pubDate>Mon, 28 Sep 2026 12:00:00 GMT</pubDate><category>info</category><category>benchmark</category><category>research</category><author>Alexandra Souly, Kai Fronsdal, Abby D&apos;Cruz, Xander Davies, Robert Kirk</author></item><item><title>Claude Desktop for macOS: Cowork files could run commands on open</title><link>https://theinjection.dev/items/anthropic-claude-desktop-cowork-file-exec/</link><guid isPermaLink="true">https://theinjection.dev/items/anthropic-claude-desktop-cowork-file-exec/</guid><description>Claude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.</description><pubDate>Fri, 25 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>vulnerability</category><author>Vladimir Tokarev, Anthropic security team</author></item><item><title>Anthropic skill scanner bypassed: malicious skills marked safe</title><link>https://theinjection.dev/items/air-anthropic-skill-scanner-bypass/</link><guid isPermaLink="true">https://theinjection.dev/items/air-anthropic-skill-scanner-bypass/</guid><description>AIR Security researchers say Anthropic&apos;s skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.</description><pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate><category>medium</category><category>attack</category><category>supply-chain</category><author>Alon Loewenstein, Ofir Birka, Shay Lempert</author></item><item><title>SalesBleed: zero-click CRM data theft through Salesforce Agentforce</title><link>https://theinjection.dev/items/zenity-salesbleed-agentforce-exfiltration/</link><guid isPermaLink="true">https://theinjection.dev/items/zenity-salesbleed-agentforce-exfiltration/</guid><description>SalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.</description><pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate><category>medium</category><category>attack</category><category>vulnerability</category><author>Alex Apostolov, João Donato, Avishai Efrat, Ayush RoyChowdhury</author></item><item><title>MemTensor MemOS packages compromised with a credential stealer</title><link>https://theinjection.dev/items/socket-memtensor-memos-compromise/</link><guid isPermaLink="true">https://theinjection.dev/items/socket-memtensor-memos-compromise/</guid><description>Malicious releases of MemTensor&apos;s MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.</description><pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>supply-chain</category><category>incident</category><author>Karlo Zanki</author></item><item><title>Explosive prompts: dormant injections fire on &apos;thanks&apos; in agents</title><link>https://theinjection.dev/items/arxiv-explosive-prompts-trigger-injections/</link><guid isPermaLink="true">https://theinjection.dev/items/arxiv-explosive-prompts-trigger-injections/</guid><description>Explosive prompts are dormant prompt injections that wait for a harmless trigger such as &apos;thanks&apos;. A new paper reports 43% to 83% success on nine production agents, versus at most 3% for plain injections, and proposes the DeFuse detector.</description><pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate><category>medium</category><category>research</category><category>attack</category><author>Justin Szczepaniak, Elad Feldman, Naum Viner, Ben Nassi</author></item><item><title>Plugin4Shell: zero-click plugin RCE in four AI coding agents</title><link>https://theinjection.dev/items/air-plugin4shell/</link><guid isPermaLink="true">https://theinjection.dev/items/air-plugin4shell/</guid><description>Plugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.</description><pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>vulnerability</category><category>supply-chain</category><author>Or Nevo, Dor Granat, Niv Hoffman</author></item><item><title>CAISI: GLM-5.3 is the most cyber-capable open-weight model yet</title><link>https://theinjection.dev/items/caisi-glm-5-3-cyber-assessment/</link><guid isPermaLink="true">https://theinjection.dev/items/caisi-glm-5-3-cyber-assessment/</guid><description>NIST&apos;s Center for AI Standards and Innovation rates Z.ai&apos;s GLM-5.3 the most cyber-capable open-weight model so far, while placing it about four months behind US frontier models on a composite cyber index.</description><pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate><category>info</category><category>benchmark</category><author>Center for AI Standards and Innovation (CAISI)</author></item><item><title>Agent Control Standard: an open spec for blocking agent actions</title><link>https://theinjection.dev/items/owasp-agent-control-standard/</link><guid isPermaLink="true">https://theinjection.dev/items/owasp-agent-control-standard/</guid><description>The Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent&apos;s tool calls and other actions before they run.</description><pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate><category>info</category><category>tool</category><author>Rock Lambros, Michael Bargury</author></item><item><title>Google GTIG: attackers used AI agents to run a credential campaign</title><link>https://theinjection.dev/items/gtig-ai-threat-tracker-prompting-to-autonomy/</link><guid isPermaLink="true">https://theinjection.dev/items/gtig-ai-threat-tracker-prompting-to-autonomy/</guid><description>Google Threat Intelligence Group reports a threat actor who planned, built and ran an agent-enabled mass credential harvesting campaign in under six hours. GTIG says it has not yet seen fully autonomous attack pipelines in the wild.</description><pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate><category>info</category><category>incident</category><category>research</category><author>Google Threat Intelligence Group</author></item><item><title>SQL Server Copilot: prompt injection escalates a user to sysadmin</title><link>https://theinjection.dev/items/embracethered-ssms-copilot-select-to-sysadmin/</link><guid isPermaLink="true">https://theinjection.dev/items/embracethered-ssms-copilot-select-to-sysadmin/</guid><description>CVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin&apos;s privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.</description><pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate><category>high</category><category>vulnerability</category><category>attack</category><author>Johann Rehberger</author></item><item><title>ChatGPT sandbox: shared package cache leaked data across accounts</title><link>https://theinjection.dev/items/checkpoint-chatgpt-shared-artifactory-channel/</link><guid isPermaLink="true">https://theinjection.dev/items/checkpoint-chatgpt-shared-artifactory-channel/</guid><description>Check Point Research found that ChatGPT code containers from different accounts shared one internal JFrog Artifactory, giving attackers a hidden channel into a victim&apos;s session and connected apps. OpenAI shut the instance down.</description><pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate><category>low</category><category>vulnerability</category><category>research</category><author>Alexey Bukhteyev</author></item><item><title>MCPJacking: 155 hijackable servers in the official MCP registry</title><link>https://theinjection.dev/items/air-mcpjacking/</link><guid isPermaLink="true">https://theinjection.dev/items/air-mcpjacking/</guid><description>MCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.</description><pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate><category>high</category><category>supply-chain</category><category>attack</category><author>Nadav Dadush, Eliad Mualem, Roi Snir</author></item></channel></rss>