Daily digest · 2026-08-13

Daily Digest, 2026-08-13

TL;DR: The tool layer under AI agents keeps failing in ways the agent itself cannot catch. A new scanner finds paths from plain English straight into shell commands on MCP servers, while researchers showed a malicious MCP server can steal SSH keys and source code by splitting the request into harmless-looking pieces. The human click-to-approve step everyone treats as a backstop misses about a third of dangerous requests. On shared hosting, one customer can time the cache and rebuild another customer's prompt, and attackers are already running agents at scale: a Chinese-speaking actor pointed a DeepSeek agent at 1,200-plus hosts at a security firm.

Top stories

Also notable