Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
CVE-2026-54316 is a vulnerability in Anthropic's Claude Code that allows an attacker to exfiltrate API keys one character at a time using…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
During a cyber evaluation by the UK's AI Security Institute (AISI), an agent running Anthropic's Claude Mythos 5 spent 34 hours attempting…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Palo Alto Networks' Unit 42 has uncovered a Chinese-speaking threat actor who leveraged the DeepSeek AI model through the open-source Hermes Agent…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…
Cybersecurity researchers have uncovered a large-scale campaign dubbed FakeGit, which leverages nearly 7,600 malicious GitHub repositories to distribute the SmartLoader malware. The…