Fetching from the wire…
Security2026-09-09 · source-backed
Google Threat Intelligence Group's Q3 2026 AI Threat Tracker documents a financially motivated actor who compromised cloud infrastructure and combined a coding chatbot, a prompt and predefined agent instructions into an autonomous vulnerability-scanning and credential-harvesting pipeline. The resulting dashboard organized and validated more than 23,800 harvested secrets including cloud and AI service credentials. GTIG also found an exposed C2 server whose directories contained AGENTS.md, KNOWLEDGE.md and .openclaw/ components. Google Cloud Threat Intelligence Attackers are now shipping the exact harness conventions we use.
Each link below shares sources, entities, or timing with this story.
July MCP roundups documented Mid-Session Tool Injection against WebMCP agents, using threshold poisoning and fabricated diagnostic events to swap or re-scope tools after a session is already established. The uncomfortable implication: a context provider you trusted at connect...
Attackers exploited CVE-2026-63077, the critical unauthenticated RCE in TeamCity On-Premises that JetBrains itself disclosed July 27, against an unpatched JetBrains-run server, reaching the Cadence cloud coding service. Because the PyCharm plugin syncs project files to Cadence...
PR #1218 in a Snowflake repository replaced a safe pattern with an unsafe one. The old code used env: plus jq --arg to pass an issue title into a shell step. The new code interpolated github.event.issue.title directly into a run: block. That's the textbook GitHub Actions scrip...
Attackers pre-register the fake package names an agent is statistically likely to invent, so when your coding assistant hallucinates a dependency, it installs attacker-controlled botnet malware. No prompt injection needed. The attacker just anticipates the model's errors and w...
A single compromised GitHub Actions workflow. That's all it took. TechCrunch reports AI recruiting startup Mercor ($10B valuation) confirmed a security incident traced back to a supply chain attack on the open-source LiteLLM proxy. The attack chain is a case study in cascading...
A critical Langflow flaw allows arbitrary Python code execution on any exposed instance with a single unauthenticated HTTP request. Sysdig observed active exploitation within 20 hours of the advisory — before any public exploit code existed. With 145K+ GitHub stars and many in...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.