Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
CoSnitch: Microsoft Copilot Personal One-Click Data Exfiltration — Detection and Remediation Guide
Introduction Varonis Threat Labs has disclosed a set of three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, th...
AI Agent 'Mind Viruses': Detecting and Containing Self-Propagating Prompt Injection in Agent Harnesses
Introduction On August 10, 2026, security researchers at Anthropic and Switzerland's EPFL released a preprint demonstrating something many o...
MCP Servers Are Leaking Enterprise Secrets: Detection and Hardening Guide for AI Agent Deployments
The Quiet Credential Leak in Your AI Stack The Model Context Protocol (MCP) has become the de facto standard for connecting AI agents to ent...
Malicious MCP Servers Splitting Instructions to Exfiltrate Secrets — Detection and Defense Guide for AI Coding Agents
Introduction A new attack technique against AI coding assistants demonstrates that defenders can no longer treat "the agent refused the mali...
Stealing Reasoning Traces from Proprietary LLM APIs: How Attackers Exfiltrate Chain-of-Thought and How to Defend Against It
Introduction A recently publicized technique demonstrates that proprietary large language model APIs — including models that deliberately su...
GhostJacking: Defending AI Agents Against Alert-Based Manipulation — Detection and Identity Governance Hardening Guide
Introduction Security researchers have disclosed a new attack technique dubbed GhostJacking that turns an organization's own security teleme...
Prompt Injection Defense: Why Transparent AI Agents Are the Detection Layer Your SOC Is Missing
Introduction A recent opinion piece on CyberScoop makes an argument that every security leader deploying AI agents needs to internalize: the...
Claude Code Auto Mode Now Default: Defending Against Prompt Injection and Unsupervised Agent Execution
Introduction Anthropic has made Auto mode the default behavior in Claude Code for Pro, Max, and Team plan subscribers, as covered in Simon W...
Atlassian Rovo Indirect Prompt Injection: Detecting and Stopping Jira/Confluence Data Exfiltration
Atlassian Rovo Prompt Injection: Your AI Assistant Is Now an Exfiltration Vector Two independent security research firms have demonstrated t...