DeskShadow Escape Zero-Click MCP AttackWweb·high signalXBlueskyLinkedInCopy linkFirst documented zero-click MCP attack. Poisoned docs cause agent data exfiltration through legitimate channels. Six-layer defense framework.↳ Follow the threadStack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubPolicy dependency / Stack layerMicrosoft publishes a 37-page 'humanist AI code of conduct' for its MAI models and opens it to public consultationThe Verge (corroborated by Unite.AI and TechBriefly)Policy dependency / Threat pattern`sec-default` puts a security boundary between an organization's managed settings and the plugins employees installGitHubStack layer / Threat patternA critical unauthenticated RCE in the Bifrost MCP gateway: registering a stdio client runs a program on the boxNVDPolicy dependency / Stack layerTarfio Launches a Budget and Metering Layer That Sits Between Agents and Paid MCP ToolsTarfio via Hacker News Show HN (single source, private beta)Policy dependency / Update threadMicrosoft Agent Framework dotnet-1.21.0 lands four breaking changes at once, including limiting MCP skill archives to ZIPGitHubPolicy dependency / Stack layerChina Drafts Embodied-AI Data Standards After 70+ Robot Training Grounds Went Up Without ThemThe Next Web