Fetching from the wire…
Security2026-08-11 · source-backed
Tenet Security showed at DEF CON 34 that Sentry's unauthenticated ingest endpoint lets anyone with a public DSN POST a crafted error event whose message fields contain markdown reading like remediation guidance. Ask Claude Code or Cursor to debug Sentry issues, and the agent pulls the injected event through MCP and executes it with local privileges. 85% success across 100+ organizations in controlled testing; 2,388 orgs found with publicly discoverable DSNs, 71 in the Tranco top-1M. Sentry added a payload-string filter but declined platform-level remediation as "technically not defensible." No CVE assigned. Mitigation repo is tenet-security/agent-jackstop, shipping deny-by-default egress allowlists.
Each link below shares sources, entities, or timing with this story.
A public DSN. That's all the attacker needs. Not your credentials, not a compromised dependency, not a phishing link. The same write-only Sentry key that's sitting in your frontend bundle right now, by design, so the browser can report errors. Tenet Security and the Cloud Secu...
Stripe added 14 providers (Render, Twilio, Sentry, WorkOS, Browserbase, GitLab, ElevenLabs) for 32 total, letting an agent provision hosting, databases, auth, and observability then bill it all through Stripe. New guardrails assign agent identities, enforce scope rules, and ro...
The Amazon Q bug is one instance of a 2026 pattern: MCP configuration carried in repositories is now an RCE supply-chain vector, not just untrusted tool output. Cursor, VS Code, Windsurf, Claude Code, and Gemini-CLI are all vulnerable to MCP-based auto-launch attacks (Windsurf...
This is the one that should make you check your own setup tonight. June MCP-security roundups flag roughly 12,520 internet-exposed MCP services, about 40% of them with no authentication at all. On top of that, Adversa AI's TrustFall and SymJack research shows that Claude Code,...
Raj Nagulapalle's FetchSandbox MCP took 107 votes on August 23, wiring 70+ API sandboxes into Cursor or Claude Code via MCP config. The claim is narrower and more testable than most agent tooling: reproduce the real integration failure against a sandbox, apply the fix, re-run...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.