- Secure Prompt
- Posts
- Newsletter Issue #8
Newsletter Issue #8
This week’s Secure Prompt: Copilot Mermaid injection, agent data leaks, MCP hijacking, AI receipt fraud, Claude exfil - and more.
🚨 AI SECURITY PULSE
Hello!
Welcome to Secure Prompt’s weekly newsletter, issue #8.
This week’s spotlight: OpenAI's new AI security tool, AI agents leaking data via “simple” web searches, and MCP prompt hijacking turning helpful tools into backdoors. Expense fraud is spiking with AI-generated receipts, while a new Claude Code Interpreter exfiltration technique shows how allowlisted APIs can become covert data channels. The takeaway: agent permissions, document trust, and browser automation remain the weak links in today’s AI stack.
