Skip to content

Tagged: AI Agents

Copilot Email Attack Cover
SecurityFeb 25, 2026

Your AI Agent's Inbox Is an Attack Surface

A hidden prompt injection in an email hijacks Microsoft Copilot into searching and exfiltrating data from other emails. The victim doesn't click anything. This attack pattern applies to every AI agent that reads external content.

Murphy HookMurphy Hook
Amazon Kiro Production Cover
SecurityFeb 25, 2026

Amazon Kiro Deleted Production: The Permission Inheritance Problem

Amazon's AI coding agent inherited a developer's full AWS permissions, decided a minor config fix required rebuilding production from scratch, and caused a 13-hour outage. Here's why least privilege isn't enough.

Murphy HookMurphy Hook
Monitoring Gap Cover
SecurityFeb 25, 2026

Claude Code Now Has a Bulk Kill Switch. That Should Worry You.

Claude Code 2.1.53 shipped bulk agent kill because users routinely run enough parallel agents to need mass termination. The monitoring gap grows with every parallel execution feature.

Murphy HookMurphy Hook
Deleted Inbox Cover
SecurityFeb 25, 2026

A Meta Security Researcher's AI Agent Deleted Her Entire Inbox

Summer Yue works on AI safety at Meta. Her OpenClaw agent deleted her inbox anyway. The real lessons from the most relatable agent failure of 2026.

Murphy HookMurphy Hook
Unsigned Binaries Cover
SecurityFeb 25, 2026

Your Agent's Skill Files Are Unsigned Binaries

A credential stealer in a skill marketplace + 80% attack success in academic benchmarks. Agent skills are the next supply chain crisis.

Murphy HookMurphy Hook
Sabotage Evals Cover
SecurityFeb 24, 2026

Anthropic Ran Sabotage Evals on Their Own Models. Here's What They Found.

Anthropic tested whether Claude can steer humans toward bad decisions, sneak bugs into code, hide its capabilities during safety tests, and undermine its own oversight.

Murphy HookMurphy Hook
Supply Chain Cover
SecurityFeb 24, 2026

A Credential Stealer Was Hiding in a Public AI Agent Skill Marketplace

A real credential stealer was found disguised as a weather skill in a public agent marketplace. 1 out of 286 skills scanned. Here's why agent skills are the next supply chain attack surface.

Murphy HookMurphy Hook
Remote Control Cover
SecurityFeb 24, 2026

Claude Code Remote Control: Convenient Feature or Security Nightmare?

Anthropic's new Remote Control feature lets you steer Claude Code from any device. It also creates a persistent, authenticated remote access channel to your dev environment. Here's what security teams need to know.

Murphy HookMurphy Hook