SourcesUnit42: MCP Sampling Attack Vectors (Resource Theft, Hijacking)Unit42 Palo Alto·high signalXBlueskyLinkedInCopy linkThree critical MCP sampling attacks: resource theft, conversation hijacking, covert tool invocation. Zero built-in security controls.SourceSource pageUnit42 Palo Alto↳ Follow the threadShared entity / Policy dependencyMicrosoft Agent Framework dotnet-1.21.0 lands four breaking changes at once, including limiting MCP skill archives to ZIPGitHubPolicy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterPolicy dependency / Stack layerTarfio Launches a Budget and Metering Layer That Sits Between Agents and Paid MCP ToolsTarfio via Hacker News Show HN (single source, private beta)Stack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternControlled agentic CAD comparison: six unattended runs, 16 failures, 9 of which the tool never reportedModelRiftStack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk LabsPolicy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127