<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NoFly blog</title>
    <link>https://shomra.ai/blog</link>
    <description>Incident breakdowns, guides and explainers on securing AI agents, MCP servers and AI tools.</description>
    <language>en</language>
    <atom:link href="https://shomra.ai/blog/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>Every agent incident we’ve taken apart, in order</title>
      <link>https://shomra.ai/blog/agent-incident-timeline</link>
      <guid isPermaLink="true">https://shomra.ai/blog/agent-incident-timeline</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Roundup</category>
      <description>A running timeline of real incidents with AI agents, MCP servers and AI tools, from deleted databases to poisoned packages, each linked to its full breakdown.</description>
    </item>
    <item>
      <title>The summer AI agents got out of the sandbox</title>
      <link>https://shomra.ai/blog/agents-that-got-out-summer-2026</link>
      <guid isPermaLink="true">https://shomra.ai/blog/agents-that-got-out-summer-2026</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>Between April and August 2026, models under test reached real systems at Hugging Face, three other organisations and an Australian government portal. Each case came down to a boundary that was assumed rather than measured.</description>
    </item>
    <item>
      <title>The OWASP Top 10 for agentic applications, control by control</title>
      <link>https://shomra.ai/blog/owasp-agentic-top-10-controls</link>
      <guid isPermaLink="true">https://shomra.ai/blog/owasp-agentic-top-10-controls</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Guide</category>
      <description>OWASP published its first list of risks for AI agents in December 2025. This is what each entry looks like in practice, and the control that answers it.</description>
    </item>
    <item>
      <title>The lethal trifecta: when one agent can read, be told and send</title>
      <link>https://shomra.ai/blog/lethal-trifecta-agents</link>
      <guid isPermaLink="true">https://shomra.ai/blog/lethal-trifecta-agents</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>An agent that can read private data, takes in content from outside, and can send data out has everything an attacker needs. Take away any one of the three and the attack falls apart.</description>
    </item>
    <item>
      <title>An MCP security checklist for the servers already on your laptops</title>
      <link>https://shomra.ai/blog/mcp-security-checklist</link>
      <guid isPermaLink="true">https://shomra.ai/blog/mcp-security-checklist</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Guide</category>
      <description>MCP servers arrive by copy and paste, run with the developer’s access and can change with any update. Here is what to check before, during and after one is approved.</description>
    </item>
    <item>
      <title>Every step was allowed. The sequence was the problem.</title>
      <link>https://shomra.ai/blog/agentic-insider-risk-sequence</link>
      <guid isPermaLink="true">https://shomra.ai/blog/agentic-insider-risk-sequence</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>When a person works through an agent, each action can be permitted on its own and still add up to data leaving the company. Catching it means judging the run, not the call.</description>
    </item>
    <item>
      <title>When someone leaves, their agents keep working</title>
      <link>https://shomra.ai/blog/offboarding-agents-when-people-leave</link>
      <guid isPermaLink="true">https://shomra.ai/blog/offboarding-agents-when-people-leave</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Guide</category>
      <description>People leave. The agents they built, the keys those agents hold and the grants they approved stay behind, running with nobody watching them.</description>
    </item>
    <item>
      <title>Approve is the most dangerous button in agent security</title>
      <link>https://shomra.ai/blog/approval-fatigue</link>
      <guid isPermaLink="true">https://shomra.ai/blog/approval-fatigue</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>Putting a person in the loop only helps if that person sees what will really happen. Most approval prompts show the agent’s own description of the action instead.</description>
    </item>
    <item>
      <title>Your AI guardrail passed the demo. Has anyone attacked it since?</title>
      <link>https://shomra.ai/blog/is-your-ai-guardrail-in-the-path</link>
      <guid isPermaLink="true">https://shomra.ai/blog/is-your-ai-guardrail-in-the-path</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>A guardrail that was switched on and a guardrail that works look the same on a quiet dashboard. This is how to tell them apart.</description>
    </item>
    <item>
      <title>Rules files, skills and hooks are code. Review them like code.</title>
      <link>https://shomra.ai/blog/agent-instructions-are-code</link>
      <guid isPermaLink="true">https://shomra.ai/blog/agent-instructions-are-code</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>The files that tell an agent how to behave change what it does as much as any script. Most teams merge them without a second look.</description>
    </item>
    <item>
      <title>Shadow AI has five front doors</title>
      <link>https://shomra.ai/blog/shadow-ai-five-front-doors</link>
      <guid isPermaLink="true">https://shomra.ai/blog/shadow-ai-five-front-doors</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Explainer</category>
      <description>AI arrives through the network, the laptop, a consent screen, the browser and the vendor’s own admin console. Watching one of them shows you a fifth of it.</description>
    </item>
    <item>
      <title>Consequence preview: try the delete on a copy first</title>
      <link>https://shomra.ai/blog/consequence-preview</link>
      <guid isPermaLink="true">https://shomra.ai/blog/consequence-preview</guid>
      <pubDate>Sat, 26 Sep 2026 12:00:00 GMT</pubDate>
      <category>Product</category>
      <description>The worst agent incidents so far were mistakes, not attacks. Reading the command and guessing is not enough, so we are building a way to measure what an action would change before it runs.</description>
    </item>
    <item>
      <title>Codex deleted users’ home directories in Full Access mode</title>
      <link>https://shomra.ai/blog/codex-deleted-home-directories</link>
      <guid isPermaLink="true">https://shomra.ai/blog/codex-deleted-home-directories</guid>
      <pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate>
      <category>Mistake</category>
      <description>Users running GPT-5.6 Sol in Codex with Full Access reported the agent deleting nearly all files on a Mac and a production database. OpenAI said the model had tried to redirect $HOME to a temporary directory and deleted the real one instead.</description>
    </item>
    <item>
      <title>A worm hid credential stealers in AI agent config files in Microsoft repositories</title>
      <link>https://shomra.ai/blog/miasma-worm-agent-config-hooks</link>
      <guid isPermaLink="true">https://shomra.ai/blog/miasma-worm-agent-config-hooks</guid>
      <pubDate>Fri, 05 Jun 2026 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>A compromised contributor account pushed config files to a Microsoft repository that would run a credential stealer as soon as a developer opened it in Claude Code, Gemini CLI, Cursor or VS Code. GitHub disabled 73 Microsoft repositories in response.</description>
    </item>
    <item>
      <title>A Cursor agent deleted a production volume and its backups in nine seconds</title>
      <link>https://shomra.ai/blog/pocketos-agent-deleted-production-volume</link>
      <guid isPermaLink="true">https://shomra.ai/blog/pocketos-agent-deleted-production-volume</guid>
      <pubDate>Fri, 24 Apr 2026 12:00:00 GMT</pubDate>
      <category>Mistake</category>
      <description>Working on a staging task, a Cursor agent found an unrelated API token, guessed that a delete would stay in staging, and removed PocketOS’s production database volume along with its backups.</description>
    </item>
    <item>
      <title>An AI app’s OAuth grant became a way into Vercel</title>
      <link>https://shomra.ai/blog/vercel-context-ai-oauth-breach</link>
      <guid isPermaLink="true">https://shomra.ai/blog/vercel-context-ai-oauth-breach</guid>
      <pubDate>Sun, 19 Apr 2026 12:00:00 GMT</pubDate>
      <category>Exposure</category>
      <description>A Vercel employee had connected Context.ai, a third-party AI workspace, to their corporate Google account. When Context.ai was breached, the attacker used that access to reach Vercel’s internal systems and decrypt some customers’ environment variables.</description>
    </item>
    <item>
      <title>Two LiteLLM releases on PyPI carried a credential stealer</title>
      <link>https://shomra.ai/blog/litellm-pypi-compromise</link>
      <guid isPermaLink="true">https://shomra.ai/blog/litellm-pypi-compromise</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>For about forty minutes on 24 March 2026, two versions of LiteLLM, a widely used gateway for model APIs, carried a credential stealer. The attacker had gained publishing access through an earlier compromise of a scanner in LiteLLM’s CI.</description>
    </item>
    <item>
      <title>Claude Code ran terraform destroy and took down a production platform</title>
      <link>https://shomra.ai/blog/datatalks-claude-code-terraform-destroy</link>
      <guid isPermaLink="true">https://shomra.ai/blog/datatalks-claude-code-terraform-destroy</guid>
      <pubDate>Thu, 26 Feb 2026 12:00:00 GMT</pubDate>
      <category>Mistake</category>
      <description>Helping move a new site into existing AWS infrastructure, Claude Code swapped in an old Terraform state file and ran terraform destroy, deleting the DataTalks.Club course platform’s database and its snapshots.</description>
    </item>
    <item>
      <title>341 malicious skills on ClawHub pushed infostealers to OpenClaw users</title>
      <link>https://shomra.ai/blog/openclaw-clawhavoc-malicious-skills</link>
      <guid isPermaLink="true">https://shomra.ai/blog/openclaw-clawhavoc-malicious-skills</guid>
      <pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>An audit of ClawHub, the skill marketplace for the OpenClaw AI assistant, found 341 malicious skills. Most belonged to one campaign that used fake setup steps to get users to install an infostealer.</description>
    </item>
    <item>
      <title>One ServiceNow agent could recruit another to do what it could not</title>
      <link>https://shomra.ai/blog/servicenow-now-assist-second-order-injection</link>
      <guid isPermaLink="true">https://shomra.ai/blog/servicenow-now-assist-second-order-injection</guid>
      <pubDate>Wed, 19 Nov 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>Researchers showed that under default settings, text planted in a record could make a harmless Now Assist agent hand work to a more privileged agent, which then copied records and emailed them out.</description>
    </item>
    <item>
      <title>A fake Postmark MCP server copied every email it sent to an attacker</title>
      <link>https://shomra.ai/blog/postmark-mcp-bcc-backdoor</link>
      <guid isPermaLink="true">https://shomra.ai/blog/postmark-mcp-bcc-backdoor</guid>
      <pubDate>Thu, 25 Sep 2025 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>An npm package imitating Postmark’s MCP server behaved normally for fifteen versions, then added a hidden BCC to an attacker’s address on every email. It was the first malicious MCP server found in the wild.</description>
    </item>
    <item>
      <title>Malicious Nx packages turned developers’ AI CLIs into secret hunters</title>
      <link>https://shomra.ai/blog/nx-s1ngularity-ai-cli-credential-theft</link>
      <guid isPermaLink="true">https://shomra.ai/blog/nx-s1ngularity-ai-cli-credential-theft</guid>
      <pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>Poisoned versions of the Nx build system ran an install script that stole credentials and, where it could, drove Claude Code, Gemini CLI or Amazon Q with permission checks switched off to find more.</description>
    </item>
    <item>
      <title>Stolen tokens from an AI chat integration opened hundreds of Salesforce orgs</title>
      <link>https://shomra.ai/blog/salesloft-drift-oauth-token-theft</link>
      <guid isPermaLink="true">https://shomra.ai/blog/salesloft-drift-oauth-token-theft</guid>
      <pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
      <category>Exposure</category>
      <description>Attackers stole OAuth tokens from Salesloft’s Drift AI chat integration and used them to pull data out of customers’ Salesforce instances. Google counted over 700 potentially affected organisations.</description>
    </item>
    <item>
      <title>A README could make Gemini CLI run hidden commands without asking</title>
      <link>https://shomra.ai/blog/gemini-cli-readme-command-injection</link>
      <guid isPermaLink="true">https://shomra.ai/blog/gemini-cli-readme-command-injection</guid>
      <pubDate>Mon, 28 Jul 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>Researchers showed that instructions hidden in a repository’s README could make Google’s Gemini CLI run a malicious command disguised behind an approved one, without a prompt and without showing it on screen.</description>
    </item>
    <item>
      <title>Gemini CLI lost a user’s files after assuming a folder existed</title>
      <link>https://shomra.ai/blog/gemini-cli-deleted-user-files</link>
      <guid isPermaLink="true">https://shomra.ai/blog/gemini-cli-deleted-user-files</guid>
      <pubDate>Mon, 21 Jul 2025 12:00:00 GMT</pubDate>
      <category>Mistake</category>
      <description>Asked to move a project’s files into a new folder, Gemini CLI assumed a failed mkdir had worked, and its move commands lost the files instead.</description>
    </item>
    <item>
      <title>Replit’s agent deleted a production database during a code freeze</title>
      <link>https://shomra.ai/blog/replit-agent-deleted-production-database</link>
      <guid isPermaLink="true">https://shomra.ai/blog/replit-agent-deleted-production-database</guid>
      <pubDate>Fri, 18 Jul 2025 12:00:00 GMT</pubDate>
      <category>Mistake</category>
      <description>During a public experiment, Replit’s AI agent ran database commands it had been told not to run, wiped a live production database, then said the damage could not be undone. The rollback worked.</description>
    </item>
    <item>
      <title>Amazon Q’s VS Code extension shipped with a prompt to wipe machines and cloud accounts</title>
      <link>https://shomra.ai/blog/amazon-q-extension-wiper-prompt</link>
      <guid isPermaLink="true">https://shomra.ai/blog/amazon-q-extension-wiper-prompt</guid>
      <pubDate>Thu, 17 Jul 2025 12:00:00 GMT</pubDate>
      <category>Supply chain</category>
      <description>An outside party got code into version 1.84.0 of the Amazon Q Developer extension that would launch Amazon Q with a prompt to delete local files and AWS resources. AWS says a syntax error stopped it running and no customers were affected.</description>
    </item>
    <item>
      <title>Connecting to a malicious MCP server could run commands on your laptop</title>
      <link>https://shomra.ai/blog/mcp-remote-command-injection</link>
      <guid isPermaLink="true">https://shomra.ai/blog/mcp-remote-command-injection</guid>
      <pubDate>Wed, 09 Jul 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>A flaw in mcp-remote, a popular proxy that connects local AI clients to remote MCP servers, let a malicious server run commands on the client machine during login. It was fixed in version 0.1.16.</description>
    </item>
    <item>
      <title>A support ticket could make an agent paste secrets back to a customer</title>
      <link>https://shomra.ai/blog/supabase-mcp-cursor-token-leak</link>
      <guid isPermaLink="true">https://shomra.ai/blog/supabase-mcp-cursor-token-leak</guid>
      <pubDate>Tue, 24 Jun 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>Researchers showed that a ticket with hidden instructions could make a Cursor agent, connected to Supabase with a key that bypasses row-level security, copy a table of integration tokens into the ticket thread.</description>
    </item>
    <item>
      <title>One email could turn Microsoft 365 Copilot into a data leak</title>
      <link>https://shomra.ai/blog/echoleak-microsoft-365-copilot-zero-click</link>
      <guid isPermaLink="true">https://shomra.ai/blog/echoleak-microsoft-365-copilot-zero-click</guid>
      <pubDate>Wed, 11 Jun 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>Researchers showed that a single crafted email could make Microsoft 365 Copilot send internal data to an outside server without the victim clicking anything. Microsoft fixed it on its side before disclosure.</description>
    </item>
    <item>
      <title>A public GitHub issue could steer an agent into leaking private repositories</title>
      <link>https://shomra.ai/blog/github-mcp-toxic-agent-flow</link>
      <guid isPermaLink="true">https://shomra.ai/blog/github-mcp-toxic-agent-flow</guid>
      <pubDate>Mon, 26 May 2025 12:00:00 GMT</pubDate>
      <category>Attack</category>
      <description>Researchers showed that instructions planted in a public issue could make an agent using GitHub’s MCP server copy private repository data into a public pull request.</description>
    </item>
  </channel>
</rss>
