Today in AI
Monday, August 17, 2026
Today in AI: MCP Servers Leak Secrets, Prompt Injection Hits Legal System — August 17, 2026
5
links
-
1thehackernews.comMCP servers expose enterprise secrets through plaintext configs, over-permissioned access, and prompt injection before security teams detect them. Practitioners deploying Claude MCP and competing agentic frameworks need inventory and access controls before data egress happens at scale.
-
2www.kunalganglani.comResearchers filed real security vulnerabilities against GitHub Copilot, Claude Code, Cursor, and five other AI coding tools by hiding malicious instructions in ordinary code files. Developers using AI coding assistants are now vectors for supply-chain compromise if their tools don't sanitize file inputs.
-
3securityaffairs.comA plaintiff hid AI prompts in court filings instructing AI systems to rule in his favor, triggering sanctions. This signals prompt injection is moving from developer tools into high-stakes adversarial contexts where AI systems read untrusted documents—legal, compliance, and gov sectors now face injection risk.
-
4thehackernews.comA GitHub Actions workflow injection in Snowflake's .NET connector repo exposed a Jira API token in a five-day window via crafted issues. CI/CD pipelines integrating with GitHub remain a high-impact attack surface for credential theft affecting AI infrastructure deployments.
-
5aitoolsreview.co.ukZ.ai's GLM 5.3 offers no published model card, safety framework, or pre-deployment risk assessment; independent testing found it refused zero offensive cyber and biology tasks. Model providers shipping without safety disclosure creates compliance and liability gaps as enterprises standardize on models for security-critical use.