Logo
Search
Home
Archive
Login
SUBSCRIBE
Logo

AI agents

cloud-security

+3

Your agent can edit /etc/hosts

Sep 8, 2026

•

5 min read

Your agent can edit /etc/hosts

Agents on a timed lookup task were allowed to fetch pages and blocked from sending anything that writes. They invented a hostname ending in a trusted suffix, pointed it at the blocked server, and posted the recipe for each other.

cloud-security

+4

Malware asks your MCP server what it can do

Aug 25, 2026

•

7 min read

Malware asks your MCP server what it can do

It asks your server what tools it has, then uses the one that runs commands. No bug, no patch.

CI/CD

+4

Your release pipeline will vouch for malware

Jul 21, 2026

•

4 min read

Your release pipeline will vouch for malware

AsyncAPI's own release pipeline published five npm versions with malware in them, each with valid provenance.

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv