NVIDIA's Open Agent Safety Platform runs Sentry, a watchdog on separate BlueField-4 cards that isolates an agent within milliseconds of crossing its boundary. For teams running coding agents, the design takes enforcement out of the agent's own process, where prompts and permission lists sit today.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence50
OX Security found 101 npm forks of the Baileys WhatsApp library, downloaded 490,000 times, that add developers' accounts to groups without consent. About a quarter of those downloads came in the last 30 days, so the campaign is still reaching new installs.
Reality
- Evidence50
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Ox Security found nearly 16% of 5,095 hostnames listed in three public MCP registries resolve outside the US, including to Russia and China. MCP has no notion of region, so cloud residency rules end where a company's AI agents connect out.
Reality
- Evidence40
- Adoption35
- Hype gap+25
- Incentives65
- Confidence45
OX Security says the packages were never meant to infect anyone who installs them. Mirrored through unpkg, they serve attacker HTML from a domain most egress policies wave through.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence65
A dev.to survey walks seven AI supply chain entry points and the named incidents behind each. The two dataset-poisoning numbers in it are the ones that should change how a model review is scoped.
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives30
- Confidence52
OX Security found that DeepSeek's coding harness would let an agent unlock itself simply by asking, because the gate trusted a name the caller supplies. That makes agent isolation a claim you have to attack before you report it as a control.
Reality
- Evidence70
- Adoption55
- Hype gap+18
- Incentives65
- Confidence60
Netskope Threat Labs puts the update between 20 and 31 July, and describes a Chrome sidebar that still earned an affiliate commission as users removed it. That says more about the update channel than about the install.
Reality
- Evidence44
- Adoption52
- Hype gap+12
- Incentives55
- Confidence46
CISA says a trojanized extension version, 18.95.0, reached a GitHub employee's machine without anyone installing it, and internal repositories left from there. CVE-2026-48027 is now in the KEV catalog.
Reality
- Evidence76
- Adoption58
- Hype gap−8
- Incentives24
- Confidence74
GitHub now sells Advanced Security as two SKUs, at $19 and $30 per active committer per month. Neither one routes a finding to an owner or enforces a deadline.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+34
- Incentives74
- Confidence33
Wiz says the VS Code extension auto-loaded MCP server configs from the workspace and handed spawned processes the developer's full environment. Fixed in language server 1.65.0.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives70
- Confidence55
The vendor reports 10-plus CVEs and up to 200,000 exposed instances, and says Anthropic declined to change the protocol, describing the behaviour as expected.
Publishers:ox.security
Reality
- Evidence32
- Adoption34
- Hype gap+46
- Incentives86
- Confidence33
Nine of eleven MCP marketplaces accepted proof-of-concept malware with zero review, and a fake agent skill cleared both Cisco's and NVIDIA's scanners to reach roughly 26,000 corporate agents.
Reality
- Evidence24
- Adoption38
- Hype gap+26
- Incentives62
- Confidence30