Fetching from the wire…
Top 5 · 2026-03-01 · source-backed
Three converging reports — IBM X-Force 2026 (AI attacks up 44%, vulnerability exploitation now #1 at 40%), Gravitee State of AI Agent Security (88% incident rate, 1.5M unmonitored agents), and Cisco AI Security 2026 (29% security-ready, MCP called "woefully insecure connective tissue") — have fully quantified the agent security crisis. Palo Alto's Unit 42 published the first formal A2A session smuggling PoC, proving agent-to-agent attacks are real, not theoretical. What to do: Implement per-agent identity, audit all agent permissions, and deploy Pipelock or nono for agent isolation.
Each link below shares sources, entities, or timing with this story.
| # | Skill | Domain | Difficulty | |---|-------|--------|------------| | 1 | Claude Code /simplify + /batch — three-agent parallel review + codebase migrations | vibe-coding | intermediate | | 2 | Pipelock agent firewall — 9-layer DLP + MCP scanning inline proxy | agent-secur...
Palo Alto Networks Unit 42 published the first formally documented agent-to-agent attack. Two PoCs demonstrate a malicious research agent tricking a financial assistant into revealing system instructions and executing unauthorized stock trades via smuggled hidden instructions....
BlueRock scanned over 7,000 MCP servers against 22-plus security rules. 36.7% carry potential server-side request forgery exposure from unrestricted outbound fetch, and 42% handle credentials insecurely. Their worked example is Microsoft's 85K-star Markitdown MCP server and it...
The MCP ecosystem now has 30 documented CVEs across six weeks spanning three attack layers: server-side injection (43%), protocol library flaws, and developer tooling vulnerabilities. Simultaneously, the AIUC-1 Consortium reports 80% of enterprises have observed risky agent be...
21. Unit 42 — A2A Session Smuggling 22. OWASP — Top 10 Agentic 23. Socket.dev — SANDWORM_MODE 24. Gravitee — Agent Security Report 25. Cisco — AI Security 2026
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.