Fetching from the wire…
Public story · 2026-08-05 · high
Researchers disclosed the gap and are pushing a two-part fix upstream into the reference scheme, per the paper.
Why now: The paper is part of the August 5 research briefing, examining the same reference scheme meant to anchor AI agent action logs in hardware trust.
Project Veraison's reference attestation scheme marks a replayed TPM quote as affirming, according to a paper posted to arXiv.
That's the mechanism meant to certify an AI agent's action log hasn't been altered after the fact. If a stale quote appraises the same as a fresh one, an audit trail built on it can't tell a live measurement from a replay.
The scheme binds the log's outcome digest into a hardware-rooted TPM quote, then checks it through a RATS-compliant verifier under RFC 9334.
The tampering checks work. Swap the recorded outcome, or flip one byte in the digest, and the verifier correctly returns contraindicated, per the paper.
What it doesn't check is whether the quote answers the challenge nonce it was just handed. An old, previously-valid quote still appraises as affirming even when nothing about the current state matches it.
The researchers disclosed the gap responsibly and describe a two-part fix meant to go upstream into the reference scheme.
Each link below shares sources, entities, or timing with this story.
Two days from now, on August 14, auto mode becomes the default permission mode for new Pro, Max, and Team sessions (Claude Code Docs, Week 32). Not opt-in. Default. Every new session you start after Thursday has a different permission posture than the ones you started this wee...
The failure that forced it: teams independently implemented auth, some with none, some API keys, some full OAuth, leaving no consistent way to authorize callers, audit actions, or offboard a departing employee (arXiv 2608.10760). The architecture crosses persona (interactive u...
This paper opens with a live failure: private keys exfiltrated from a widely deployed agent framework via email injection, because the keys sat in software-readable storage the agent could reach. Their five-layer zero-trust MCP stack ends in a hardware execution boundary (HSM/...
arXiv 2608.06130 opens with a production incident where keys were exfiltrated from a widely deployed agent framework via email injection in under five minutes. The design confines keys to an HSM, TPM or smart card behind vendor-neutral PKCS#11 so the host only handles opaque h...
Thinkingbox is an MCP-compatible sandbox with isolated sessions, full execution traces, and outcome evaluation against terminal backend state, carrying 507 policy-conditioned workflows across retail, hospitality, auto insurance, neobank internal IT and consulting support (arXi...
The failure they target is specific and under-discussed: a cached error page or a negative price returns in the *expected schema* and gets consumed as fact, unlike a timeout the agent can see. Outcome Monitors check results against contracts mined from task-disjoint traces or...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.