Today in AI: MCP Servers Leak Secrets, Prompt Injection Hits Legal System — August 17, 2026

August 17, 2026 — curated links and takeaways.

1. How MCP Servers Can Expose Enterprise Secrets

MCP servers expose enterprise secrets through plaintext configs, over-permissioned access, and prompt injection before security teams detect them. Practitioners deploying Claude MCP and competing agentic frameworks need inventory and access controls before data egress happens at scale.

2. Advanced Prompt Injection Techniques 2026: 7 Attack Chains

Researchers filed real security vulnerabilities against GitHub Copilot, Claude Code, Cursor, and five other AI coding tools by hiding malicious instructions in ordinary code files. Developers using AI coding assistants are now vectors for supply-chain compromise if their tools don't sanitize file inputs.

3. Invisible AI Prompts Trigger Court Sanctions

A plaintiff hid AI prompts in court filings instructing AI systems to rule in his favor, triggering sanctions. This signals prompt injection is moving from developer tools into high-stakes adversarial contexts where AI systems read untrusted documents—legal, compliance, and gov sectors now face injection risk.

4. Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

A GitHub Actions workflow injection in Snowflake's .NET connector repo exposed a Jira API token in a five-day window via crafted issues. CI/CD pipelines integrating with GitHub remain a high-impact attack surface for credential theft affecting AI infrastructure deployments.

5. GLM 5.3 Review: Benchmarks, Cyber Risk & Pricing (August 2026)

Z.ai's GLM 5.3 offers no published model card, safety framework, or pre-deployment risk assessment; independent testing found it refused zero offensive cyber and biology tasks. Model providers shipping without safety disclosure creates compliance and liability gaps as enterprises standardize on models for security-critical use.