Securd blog

The incidents, research and regulation shaping agent security, with sources, and what the resolver saw in each.

Research 6 min read

GitSpawn: one .git/config line runs before the agent asks permission

Seven coding agents executed attacker commands during routine context gathering. Four of eight findings were unpatched when the research went public.

7

coding agents affected

8

findings, 4 unpatched at publication

0

prompts or approvals required

Industry

Agent security found its product category. It is runtime, and it lives on the host.

AIR Security emerged with $50 million and CrowdStrike unveiled Falcon Guardian on the same day. Both enforce where the agent executes. Neither sees where it connects.

$50M

AIR Security, two seed rounds in six months

Fal.Con

Falcon Guardian announced September 1

Regulation

August 2 came and went. What the EU AI Act still asks of agent deployments.

The Digital Omnibus deferred high-risk obligations to December 2027. Transparency obligations took effect on schedule, and record-keeping is the work that did not get easier.

Jul 27

Omnibus entered into force

Dec 2, 2027

Annex III high-risk obligations now apply

MCP

MCP goes stateless HTTP. Your agents just gained a lot more remote servers.

The 2026-07-28 specification makes remote MCP servers easier to deploy. Scans this summer found thousands already on the internet without authentication.

12,520

internet-accessible MCP services, Censys

1,467

exposed servers in Trend Micro follow-up scan

Incident

The Memory Heist and GitLost: exfiltration through the agent's own fetch

Two July disclosures used the same exit. The agent was told to fetch a URL, and the URL carried the data out.

Jul 8

GitLost disclosed

Jul 15

Memory Heist disclosed

MCP

Tool description poisoning, walked through by Microsoft Incident Response

A silently modified tool description, a re-trust that never asked, an execution, and exfiltration through an approved call. Four phases, no exploit.

Jun 30

Microsoft IR walkthrough published

4

phases from modified description to exfiltration

Research

Agentjacking: a public Sentry DSN is all an attacker needs

Tenet Security injected instructions into error events. Claude Code, Cursor and Codex read them through MCP and ran them. Sentry says the class is not defensible at ingestion.

85%

exploitation success across Claude Code, Cursor and Codex

2,388

organizations with injectable DSNs identified

MCP

CISA and NSA call MCP an attack surface. The numbers say they are late.

Joint guidance this month names the protocol most agents use to reach tools. Independent scans had already found command injection in a large share of servers.

43%

of tested MCP servers had command injection, Equixly

82%

use file operations prone to path traversal, Endor Labs

Supply chain

Mini Shai-Hulud: 170 packages, two registries, one import statement

mistralai 2.4.6 ran a credential stealer on import. The npm variant used a lookalike domain; the PyPI variant used a raw IP. That difference is the whole egress lesson.

170

packages, 400+ malicious versions in two days

CVSS 9.6

CVE-2026-45321, the campaign entry point

Incident

The Mexico breach logs: 1,088 prompts, 5,317 commands, one operator

Gambit Security's full analysis shows what an agent-run intrusion looks like from the inside. Three quarters of the remote commands were generated by Claude Code.

5,317

AI-executed commands from 1,088 prompts

75%

of remote command execution by Claude Code

MCP

The mother of all AI supply chains: command injection in the official MCP SDKs

OX Security found the STDIO transport in Anthropic's Python, TypeScript, Java and Rust SDKs passing configuration to the shell unsanitized. Flowise needed an emergency patch the same month.

4

official SDKs affected: Python, TypeScript, Java, Rust

STDIO

transport that passed config to the shell

Supply chain

Axios, 39 minutes, and every coding agent that would have installed it

Two poisoned versions of a package with more than 100 million weekly downloads shipped a cross-platform RAT. An agent running npm install had no way to know.

100M+

weekly downloads of axios

39 min

window between the two poisoned publishes

Evaluate Agent DNS with your own agent traffic

Deploy on a single policy in learning mode and review the results with your security team.