Fetching from the wire…
Public story · 2026-03-11 · source-backed
A command injection vulnerability in ModelScope's MS-Agent lets attackers hijack agent workflows via crafted inputs in prompts, documents, or logs — the check_safe() regex denylist is bypassable. This is a new failure class: indirect prompt-to-tool-to-shell compromise. Unpatched. PoC available on GitHub. SecQube
Each link below shares sources, entities, or timing with this story.
A disclosed Cursor vulnerability let an attacker poison the agent's execution environment so an allowlisted command delivered an arbitrary payload. The allowlist made the attack *easier*, because it auto-approved exactly the command the attacker needed. (Lushbinary) Command al...
The highest-signal thought leader content this session. Bargury's two posts (Feb 18-19) document the Clinejection attack in forensic detail using his Raptor AI agent. He traced the attack chain in 5 minutes: malicious GitHub issue title → prompt injection in Claude triage bot...
Rietta's post-mortem for CVE-2026-66066, a 9.5 in Rails 8+ ActiveStorage, is the most useful incident writeup I've read this month. They deployed the patch at 11:09 PM EST on July 29. The first attack against a state government Rails site they host arrived at 7:10:25 AM the ne...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
Check Point Research disclosed CVE-2025-59536 and CVE-2026-21852 — two vulnerabilities that weaponize Claude Code's project configuration system against its users. This matters because an Agents Anonymous survey this week showed 90% of practitioners at their SF meetup use Clau...
GHSA-533j-2v4q-mw5h (CVE-2026-55253, CVSS 7.7) covers MongoDBSaver.list() and MongoDBStore.search() accepting a filter without rejecting $-prefixed MongoDB operator keys, letting a caller who controls the filter read checkpoints outside their thread scope. Fixed in langgraph-c...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.