Image
Episode 31  •  Aug 21, 2026  •  36 Min

Spliced Instructions, Recycled Bugs, Leaked Addresses & Sold Directories

Four stories on the table this week. A malicious MCP server split a single data theft instruction across two messages and got AI coding agents to exfiltrate secrets anyway. A researcher dropped a GeoServer SQL injection zero-day that turned out to be a three-year-old bug wearing a new function. A hardware wallet company's shipping vendor got breached, exposing the physical addresses of thousands of crypto holders. And a threat actor is selling employee directories pulled from nine Fortune 500 companies' Azure tenants, with no platform vulnerability involved. Here's what stood out from the operator chair.

You don't need to jailbreak the model. You just need to get it to borrow another model's clearance badge. Ghost Splice splits a data-theft instruction between a tool description and a later tool result so no single message looks malicious, and it worked: average compliance across 11 tested models jumped from 42% to 82%. It only works once a developer already trusted the malicious MCP server enough to connect it, so the real exposure is that decision, not the model's judgment in the moment.

Patching the function that got the CVE doesn't mean you audited the pattern that caused it. A publicly dropped SQL injection zero-day in GeoServer's JSON array-contains function, a near-identical regression of a flaw GeoServer patched in 2023, had botnets probing within hours and more than 1,500 exposed instances scanned worldwide. A three-year-old fix closed one function, not the sanitization logic behind it, and whoever inherited that codebase without the original incident's context had no reason to go looking for siblings. If you're running GeoServer as system admin with PostGIS enabled, assume RCE, not just SQL injection.

A breach in a shipping vendor's analytics dashboard now tells someone exactly where the hardware wallets live. Trezor disclosed its fulfillment partner Shipmunk was breached through a maximum severity SQL injection zero-day in Metabase, exposing names, emails, phone numbers, and shipping addresses for roughly 13,700 customers who ordered between May and August. No seed phrases or firmware were touched, but a physical address tied to a device built to hold cryptocurrency is its own kind of exposure. Vendor risk assessments that stop at whether a partner touches your core systems miss the fulfillment vendor that quietly knows where the money lives.

Reset every password you want. The org chart isn't going anywhere. A threat actor calling themselves The Hat Man is selling millions of employee directory records allegedly pulled from the Azure and Entra tenants of at least nine Fortune 500 companies, including more than 1.7 million records from McDonald's alone, with no platform vulnerability involved, just stolen credentials and thin MFA enforcement on a legacy API. Job titles, managers, service accounts, and global admin listings hand an attacker a ready-made map for the next phishing run or privilege escalation attempt, and unlike a password, an org chart survives the incident response.

Security Headlines:


Sean McMillan Headshot

Sean McMillan

Community Manager

Sean McMillan is Community Manager at Bishop Fox, focused on making complex security topics easier to understand and more interesting to follow. He holds a bachelor’s degree in Mass Communication and Media Studies from Arizona State University and brings over a decade of experience in podcasting, live hosting, and audience engagement. As host of Initial Access, he works with practitioners to explore how real-world attacks actually happen.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Emilio Gallegos Bio Image

Emilio Gallegos

Adversarial Operator

Emilio Gallegos is an offensive security researcher and adversarial operator at Bishop Fox. He specializes in application security and vulnerability discovery, earning notable recognition on the Apple Web Server Security Acknowledgements list and discovering CVE-2026-25087, a denial-of-service vulnerability in Apache Arrow.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere