This week in the Wild West Roundup:
- This week in the Wild West Roundup:
- When even mainstream news publications are having exclusives on gaping security holes in agentic systems, you know it's shooting fish in a barrel…
- "After loading a project, Cursor attempts to find git binaries at various locations including the current workspace.
- By creating a repository with a planted malicious git.exe in the root, the IDE will execute it with no user interaction and no prompting of the user.
- This occurs repeatedly on a cadence."
- "The instruction to steal your .env lives inside a PNG.
- Text-based reviewers see a binary blob.
- The coding agent reads it, and later writes your whole .env into the source as a list of numbers."
- HalluSquatting: Squatting on common hallucinations with malicious instructions.
- "We show that attackers can exploit predictable LLM hallucinations of resource identifiers to launch scalable, untargeted prompt injection attacks without requiring any direct channel to LLM applications.
- By preemptively registering hallucinated resources—a technique we call adversarial hallucination squatting (HalluSquatting)—we demonstrate remote tool execution and remote code execution at scale across a range of popular agentic LLM applications, which could be exploited to the establishment of a botnet."
- In-the-wild attacks, including ones targeting payments.
- "A DigiCert survey reveals that 78% of IT leaders have faced AI-related security incidents in the past six months, though only half have implemented formal governance programs."