Fetching from the wire…
Public story · 2026-03-05 · source-backed
Each link below shares sources, entities, or timing with this story.
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
Vercel's skills.sh marketplace (69K+ skills) now has triple-layer security: Snyk scans (catching prompt injection in 36% of skills), Gen/Norton Agent Trust Hub (4-tier risk ratings), and Socket supply chain analysis (94.5% precision). Cisco open-sourced both a skill-scanner an...
1. Harden CI/CD Pipelines Against PromptPwnd AI Injection | Intermediate Aikido Security disclosed "PromptPwnd" — five Fortune 500 companies confirmed affected by AI agent injection in GitHub Actions. 1. Audit all .github/workflows/ for user-controlled input (github.event.issu...
Thirty CVEs in sixty days. That's the MCP ecosystem's security track record for 2026 so far, and the severity is climbing. Three disclosures dropped this week that should make anyone running agent infrastructure pause. First, PraisonAI, a popular multi-agent orchestration fram...
1. AWS Security Blog — FortiGate Campaign 2. The Hacker News — FortiGate Coverage 3. BleepingComputer — FortiGate 4. mbgsec.com — Clinejection Post-Mortem 5. Snyk — Cline Supply Chain Attack 6. Fortune — Pentagon-Anthropic 7. NBC News — Anthropic Defense 8. Anthropic — The Bri...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.