AgentsCrowdStrike 2026 Global Threat Report AI Attacks Up 89%CrowdStrike·high signalXBlueskyLinkedInCopy linkAI-enabled adversary ops up 89% YoY. Fastest breakout 27 seconds. DeepSeek-R1 produces 50% more vulnerable code on politically sensitive prompts. 90+ orgs exploited via prompt injection.SourceSource pageCrowdStrike↳ Follow the threadPolicy dependency / Stack layerAttnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPRarXivPolicy dependency / Stack layerA controlled ablation on a production science agent finds the model choice dominates topology and prompting, and a PPO policy nearly matches it for freearXivPolicy dependency / Stack layerBorrowed Authority: Agent Skills Carry No Typed Way to Reject a Permission Claim, and Edge Skillguard Rejects 60/60 AttacksarXiv 2608.25091Policy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivStack layer / Threat patternClaude Code ships /claude-api cost-optimize, a skill that profiles an existing project's API spend one measured change at a timeClaude Code changelogPolicy dependency / Stack layerSMITH Trains Tool Creation and Tool Use in One Policy; a 4B Qwen3 Beats an Untrained 30B Tool-Writer at 79.8 Macro AccuracyarXiv 2608.24571Stack layer / Threat patternCline v4.1.16 fixes hooks resolving from global state, and starts redacting credentials embedded in git remote URLs before they reach the modelGitHub (cline/cline)Policy dependency / Stack layerBest Practice Critic Optimization Matches GRPO While Sampling One Response Per PromptarXiv 2608.23566