AgentsUnit 42 Agent Session Smuggling A2A Attack PoCPalo Alto Networks·high signalXBlueskyLinkedInCopy linkFirst formally documented agent-to-agent attack from major security vendor. PoCs demonstrate financial assistant manipulation via session injection.SourceSource pagePalo Alto Networks↳ Follow the threadPolicy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivPolicy dependency / Stack layerLMSM Ports the Linux Security Modules Split to LLM Serving, Cutting HarmBench ASR 39.20% to 3.32% at 98.14% ThroughputarXiv 2608.25697Stack layer / Threat patternGoogle Cloud Shipped Gemini Enterprise for Financial Services With 50 Skills, 13 Connectors and a Partner Agent MarketplaceGoogle Cloud Blog (corroborated by PRNewswire, 2026-08-25 12:00)Stack layer / Threat patternVS Code 1.135 shows Copilot and Claude agent sessions started in other apps, and adds a second-opinion model commandVisual Studio CodeStack layer / Threat patternPostHog Shipped a Desktop Agent IDE, Turning an Analytics Vendor Into a Coding-Agent VendorPostHog (corroborated by Product Hunt daily leaderboard, 2026-08-26)Stack layer / Threat patternTrojanized pantheon-agents wheels on PyPI ship a Bun-based credential stealer, GitHub source untouchedGitHub Advisory DatabaseStack layer / Threat patternClaude Code 2.1.247 Stops Subagents From Dying on a First-Call Model 404Claude Code ChangelogStack layer / Threat patternOpenAI's official Hugging Face incident report says its own CoT monitor would have paged security more than a day before the breachOpenAI, with detail from TechCrunch and Hacker News item 49454314