NewsMCP Sampling Attack Vectors Resource Theft Conversation HijackingUnit42·high signalXBlueskyLinkedInCopy linkUnit42 identifies three MCP sampling attack patterns: resource theft, conversation hijacking, covert tool invocation. Root cause: MCP sampling lacks security controls.SourceSource pageUnit42↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Shared entity / Stack layerClaude Code MCP servers configured as `http` never connected if the server only spoke legacy HTTP+SSEGitHubPolicy dependency / Stack layerPattern: the agent config layer is being treated as an unmanaged dependency graph, and three independent sources said so this weekarXivStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivPolicy dependency / Stack layerMemSentry gates persistent memory writes on a signed security-state delta rather than on content classificationarXivPolicy dependency / Stack layerMCP Inspector 2.6.0 raised its declared hono floor rather than trusting its lockfile, and documented whyGitHubStack layer / Threat patternFrontier models now learn arbitrary ciphers from prompting alone, and encrypted harmful content slips past commercial classifiers as gibberisharXiv 2609.09553Stack layer / Threat patternA weaker agent recovered 80% of a stronger proprietary agent's capability gap from black-box execution differences alonearXiv 2609.07131