Securd blog
The incidents, research and regulation shaping agent security, with sources, and what the resolver saw in each.
GitSpawn: one .git/config line runs before the agent asks permission
Seven coding agents executed attacker commands during routine context gathering. Four of eight findings were unpatched when the research went public.
7
coding agents affected
8
findings, 4 unpatched at publication
0
prompts or approvals required
Agent security found its product category. It is runtime, and it lives on the host.
AIR Security emerged with $50 million and CrowdStrike unveiled Falcon Guardian on the same day. Both enforce where the agent executes. Neither sees where it connects.
$50M
AIR Security, two seed rounds in six months
Fal.Con
Falcon Guardian announced September 1
August 2 came and went. What the EU AI Act still asks of agent deployments.
The Digital Omnibus deferred high-risk obligations to December 2027. Transparency obligations took effect on schedule, and record-keeping is the work that did not get easier.
Jul 27
Omnibus entered into force
Dec 2, 2027
Annex III high-risk obligations now apply
MCP goes stateless HTTP. Your agents just gained a lot more remote servers.
The 2026-07-28 specification makes remote MCP servers easier to deploy. Scans this summer found thousands already on the internet without authentication.
12,520
internet-accessible MCP services, Censys
1,467
exposed servers in Trend Micro follow-up scan
The Memory Heist and GitLost: exfiltration through the agent's own fetch
Two July disclosures used the same exit. The agent was told to fetch a URL, and the URL carried the data out.
Jul 8
GitLost disclosed
Jul 15
Memory Heist disclosed
Tool description poisoning, walked through by Microsoft Incident Response
A silently modified tool description, a re-trust that never asked, an execution, and exfiltration through an approved call. Four phases, no exploit.
Jun 30
Microsoft IR walkthrough published
4
phases from modified description to exfiltration
Agentjacking: a public Sentry DSN is all an attacker needs
Tenet Security injected instructions into error events. Claude Code, Cursor and Codex read them through MCP and ran them. Sentry says the class is not defensible at ingestion.
85%
exploitation success across Claude Code, Cursor and Codex
2,388
organizations with injectable DSNs identified
CISA and NSA call MCP an attack surface. The numbers say they are late.
Joint guidance this month names the protocol most agents use to reach tools. Independent scans had already found command injection in a large share of servers.
43%
of tested MCP servers had command injection, Equixly
82%
use file operations prone to path traversal, Endor Labs
Mini Shai-Hulud: 170 packages, two registries, one import statement
mistralai 2.4.6 ran a credential stealer on import. The npm variant used a lookalike domain; the PyPI variant used a raw IP. That difference is the whole egress lesson.
170
packages, 400+ malicious versions in two days
CVSS 9.6
CVE-2026-45321, the campaign entry point
The Mexico breach logs: 1,088 prompts, 5,317 commands, one operator
Gambit Security's full analysis shows what an agent-run intrusion looks like from the inside. Three quarters of the remote commands were generated by Claude Code.
5,317
AI-executed commands from 1,088 prompts
75%
of remote command execution by Claude Code
The mother of all AI supply chains: command injection in the official MCP SDKs
OX Security found the STDIO transport in Anthropic's Python, TypeScript, Java and Rust SDKs passing configuration to the shell unsanitized. Flowise needed an emergency patch the same month.
4
official SDKs affected: Python, TypeScript, Java, Rust
STDIO
transport that passed config to the shell
Axios, 39 minutes, and every coding agent that would have installed it
Two poisoned versions of a package with more than 100 million weekly downloads shipped a cross-platform RAT. An agent running npm install had no way to know.
100M+
weekly downloads of axios
39 min
window between the two poisoned publishes
DNS security fundamentals
Evaluate Agent DNS with your own agent traffic
Deploy on a single policy in learning mode and review the results with your security team.