Fetching from the wire…
Public story · 2026-02-25 · source-backed
CrowdStrike's 2026 Global Threat Report shows 89% YoY increase in AI-enabled attacks, with average breakout time falling to 29 minutes (65% faster than 2024). Fastest recorded: 27 seconds. Data exfiltration began within 4 minutes in one case. Critically for builders: attackers are weaponizing victims' own local AI tools (Claude CLI and Gemini CLI) by shipping malicious npm packages that instruct these tools to steal credentials and cryptocurrency. Action: Treat AI CLI tools with terminal access as privileged attack surface. Vet npm dependencies. (GBHackers, CybersecurityNews)
Each link below shares sources, entities, or timing with this story.
CVE-2026-27896 (MCP Go SDK): High-severity interpretation conflict in the *official* MCP Go SDK (maintained by Anthropic + Google). Go's encoding/json performs case-insensitive matching — attackers bypass WAFs by sending JSON-RPC messages with non-standard casing the SDK accep...
The agent business model showed up this week, and it's rent. At Knowledge 2026, ServiceNow launched Action Fabric, a layer that every external AI agent must pass through to read data or run workflows inside the ServiceNow platform, metered on action-based pricing (ServiceNow N...
A single PR title. A hidden HTML comment in an issue body. No jailbreak, no social engineering, no user interaction required. Your credentials get exfiltrated through GitHub's own infrastructure before you ever see the notification. Security researcher Aonan Guan (Wyze Labs) a...
Fairwind, announced September 2, gives governments, national cyber authorities, critical infrastructure operators and core technology platforms access to Gemini 3.8 Flash Cyber and the CodeMender harness for finding, verifying and fixing vulnerabilities. Google names more than...
OpenAI published "A call for collective action on cyber defense" on August 27, co-signed by Anthropic, Google, Microsoft, Amazon, Cisco, Oracle, Cloudflare, CrowdStrike and Palo Alto Networks, plus non-tech signatories including Capital One, Mastercard, Visa, General Motors an...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.