Fetching from the wire…
Security2026-07-29 · source-backed
Proofpoint documented indirect prompt injection tooling advertised on closed criminal forums with subscriptions starting around $150/month. The kits bundle IDPI generators for email, PDF, calendar invites, and web pages: white-on-white text, prompts hidden in meeting agenda fields that fire when an agent summarizes the invite, instructions embedded in ad HTML via alt-text and tiny fonts. Proofpoint calls the techniques still experimental. The move from conference demo to priced commodity is the part that matters, because it means the attacker no longer needs to be clever.
Each link below shares sources, entities, or timing with this story.
86,600 stars. Six third-party plugin repos above 450 stars. Two of them created *before* the public repo existed. DeepSeek released DeepSeek Harness (dsh) on August 13 under MIT. Every capability is a swappable plugin: models, tools, skills, sessions, sandboxes, storage, loops...
First cybersecurity platform for comprehensive agentic workspace protection. Acuvity provides: MCP server visibility and enforcement, AI-powered intent detection, shadow AI discovery, and sensitive data exposure prevention for locally installed AI tools (OpenClaw, Ollama). Fil...
Two thirds. Not two thirds of a contrived jailbreak set. Two thirds of realistic malicious issue requests, against the exact three tools most of the people reading this run daily. Ankur Singh, Jinqiu Yang, and Tse-Hsun Chen built IssueTrojanBench across four attack categories...
Of 53 tracked agentic projects, 28 are coding agents, and the five fastest-growing tools, Claude Code, Gemini CLI, Codex, Cline, and Aider, are all in that category (Help Net Security). Security advisories cluster around n8n (57), Claude Code (22), AutoGPT (15), Dify (13), and...
On a verifiable protein-function characterization task routed across tools, model choice swamped federation topology, RL-versus-LLM harness, and prompt expertise: Opus at roughly 92 to 94%, o4-mini at 40 to 50%. Federation across institutional boundaries cost almost nothing (a...
HumanLayer published the skill on August 12 with the framing that "agents got more intelligent on paper, but the experience of using them got noticeably worse." Invoking it directs replies into component trees, call stacks, diagrams, file layouts, pseudocode, type signatures,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.