NewsMCP Sampling Attack Vectors Resource Theft Conversation HijackingUnit42·high signalXBlueskyLinkedInCopy linkUnit42 identifies three MCP sampling attack patterns: resource theft, conversation hijacking, covert tool invocation. Root cause: MCP sampling lacks security controls.SourceSource pageUnit42↳ Follow the threadStack layer / Threat patternElva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo CommitsElva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)Stack layer / Threat patternRemoving the Tenant ID From an MCP Tool Schema Blocks Cross-Tenant Reads That a Validated Parameter Let Through 26 Times Out of 26arXiv 2609.14780Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternn8n 2.40.0 preserves empty-text Anthropic thinking blocks across tool calls and enforces execution timeouts on stuck queue jobsGitHubStack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk LabsPolicy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Stack layer / Threat patternCline desktop 0.0.27 fixes sign-out that silently undid itself and per-model protocol routing that broke every OpenCode Go modelGitHubThreat pattern / ContrastActGuard audits the planned action instead of filtering tool output, comparing each step against a local tool priorarXiv