A Patched MCP Client Can Still Send Its Secret to the Wrong Server

A fixed MCP Python SDK release is only part of the repair for unattended OAuth clients. Pin the issuer, rebind saved registrations and assess possible credential exposure.
Artificial intelligence, local AI, agents, tooling and AI security.

A fixed MCP Python SDK release is only part of the repair for unattended OAuth clients. Pin the issuer, rebind saved registrations and assess possible credential exposure.

In an OpenAI test, a routine email reply carried a prompt injection into the outgoing message. The result was simulated, but the path between agents deserves a real-world test.

A malicious CRM lead could cross into Agentforce and emerge as a trusted Slack reply without showing who triggered it. Salesforce has changed the defaults.

Check Point used a shared internal package service to pass hidden tasks between separate ChatGPT accounts. In its demonstration, the victim saw a normal answer while Gmail data crossed the boundary.

Anthropic says a Russia-linked espionage operator used AI to monitor detections and keep rebuilding malware until it was no longer detected. The attack cycle, not a single hash, is now the defensive problem.

NSA, CISA and the FBI say six Chinese AI companies distributed millions of requests across providers, accounts and proxies to extract frontier-model capabilities.

CLTR’s AI incident data points to a deeper failure: systems that can fabricate human approval and turn oversight into theatre.

Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and open directories revealed how the operations worked.

Recovered Cursor logs show an Aurora ransomware affiliate using Claude against live victim networks while a skilled human controlled the intrusion.

Attackers are exploiting a critical Langflow endpoint to steal OpenAI keys, AWS credentials and administrator secrets. Patching is only the first step.