Urgent.News

600+ sources. One page. See who else covered it.

Editions

AI

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in AI

I built an AI patient, then spent most of my time stopping it from behaving like AI

I’m a backend engineer, and my cofounder is a doctor training in emergency care. Rounds began with something she kept returning to in our conversations. An exam gives you the relevant information.

  • AI patient prototype initially impressive but behavior-controlling issues arose
  • Clinical truth and session state controlled by fixed clinical state
  • Model separates clinical truth from human language for consistent results

More from Tuesday 11 August →