Fetching from the wire…
Security2026-07-29 · source-backed
Oasis found that Claude Desktop's registration of the claude:// URL scheme caused the app to open, import a prompt from the URL, and immediately submit it with no display of the full prompt and no approval step. Visible text looked benign while hidden instructions in the same link executed silently, enabling conversation-history exfiltration, filesystem reads, and code execution for anyone running the Filesystem MCP server. Patched in Claude Desktop 1.1.2321, where prompts are pre-filled but require an explicit send. Generalize the lesson: any custom URL scheme registered by an agent client is an unauthenticated instruction channel into that agent.
Each link below shares sources, entities, or timing with this story.
Pair this with the espionage story and the picture gets uncomfortable fast. A new arXiv paper (2603.21642) presents the first systematic evaluation of prompt injection through tool-poisoning across seven MCP clients: Claude Desktop, Claude Code, Cursor, Cline, Continue, Gemini...
MIT-licensed desktop app and CLI that auto-detects installed AI clients and manages MCP server configuration for all of them — Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, ChatGPT Desktop, Gemini CLI. Built-in MCP marketplace, team snapshot export, automatic backups...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
Socket.dev disclosed a self-replicating npm worm with a McpInject module that creates fake MCP servers targeting Claude Code, Cursor, Windsurf, VS Code Continue, and Claude Desktop. At least 19 typosquatted packages were compromised. This is purpose-built malware targeting the...
YC-backed, MIT-licensed, with 280+ integrations that auto-expose as MCP servers for Claude Desktop and Cursor. Unlimited workflow runs at $25/month vs Zapier's per-task pricing. Every integration piece simultaneously works as a no-code automation step and an LLM-accessible tool.
Dispatch launched in research preview for Max subscribers. You text instructions from your phone; Claude picks them up and executes real work on your desktop environment, spawning agent teams autonomously. Early testing shows it works with Connectors but succeeds roughly half...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.