Four stories on the table this week. A malicious MCP server split a single data theft instruction across two messages and got AI coding agents to exfiltrate secrets anyway. A researcher dropped a GeoServer SQL injection zero-day that turned out to be a three-year-old bug wearing a new function. A hardware wallet company's shipping vendor got breached, exposing the physical addresses of thousands of crypto holders. And a threat actor is selling employee directories pulled from nine Fortune 500 companies' Azure tenants, with no platform vulnerability involved. Here's what stood out from the operator chair.
You don't need to jailbreak the model. You just need to get it to borrow another model's clearance badge. Ghost Splice splits a data-theft instruction between a tool description and a later tool result so no single message looks malicious, and it worked: average compliance across 11 tested models jumped from 42% to 82%. It only works once a developer already trusted the malicious MCP server enough to connect it, so the real exposure is that decision, not the model's judgment in the moment.
Patching the function that got the CVE doesn't mean you audited the pattern that caused it. A publicly dropped SQL injection zero-day in GeoServer's JSON array-contains function, a near-identical regression of a flaw GeoServer patched in 2023, had botnets probing within hours and more than 1,500 exposed instances scanned worldwide. A three-year-old fix closed one function, not the sanitization logic behind it, and whoever inherited that codebase without the original incident's context had no reason to go looking for siblings. If you're running GeoServer as system admin with PostGIS enabled, assume RCE, not just SQL injection.
A breach in a shipping vendor's analytics dashboard now tells someone exactly where the hardware wallets live. Trezor disclosed its fulfillment partner Shipmunk was breached through a maximum severity SQL injection zero-day in Metabase, exposing names, emails, phone numbers, and shipping addresses for roughly 13,700 customers who ordered between May and August. No seed phrases or firmware were touched, but a physical address tied to a device built to hold cryptocurrency is its own kind of exposure. Vendor risk assessments that stop at whether a partner touches your core systems miss the fulfillment vendor that quietly knows where the money lives.
Reset every password you want. The org chart isn't going anywhere. A threat actor calling themselves The Hat Man is selling millions of employee directory records allegedly pulled from the Azure and Entra tenants of at least nine Fortune 500 companies, including more than 1.7 million records from McDonald's alone, with no platform vulnerability involved, just stolen credentials and thin MFA enforcement on a legacy API. Job titles, managers, service accounts, and global admin listings hand an attacker a ready-made map for the next phishing run or privilege escalation attempt, and unlike a password, an org chart survives the incident response.
Security Headlines:
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.