I've seen a bunch of attempts at this but it's basically an impossible problem to solve If your scanner only detects 90% of attacks it's virtually useless, because an adversarial attacker will keep trying until they find one of the 1/10 attacks that work https://
simonwillison.net/2025/Aug/9/bay
-area-ai/#the-lethal-trifecta.018.jpeg
…
CYBERSECURITY
-

Scanner Security Limitations Against Adversarial Attacks
By
–
-
Developer JWT Token Theft from Hardcoded Source Code
By
–
Correction to this thread: I said the developer secrets were stolen from environment variables but actually it looks
like they stole a JWT token that was hard-coded in source code. More of my notes here: -
Prompt Injection and MCP Security: Emerging Threats
By
–
I gave a talk on Wednesday at the Bay Area AI Security Meetup about prompt injection, MCP security and the lethal trifecta. Here are the annotated slides from my presentation, including notes on my weird hobby of trying to coin or amplify new terms of art
-
Mitigating AI Security Risks: The Lethal Trifecta Solution
By
–
The only solution I know of to the lethal trifecta is to cut off one of the three legs – when Cursor say "limit to those that access trusted content" they're recommending avoiding exposure to untrusted data that might contain malicious instructions, which is often very hard to do
-
Cursor AI Tool Targeted in Lethal Trifecta Security Attack
By
–
This was in response to a classic lethal trifecta attack – here an attacker filed a Jira issue (via a support ticket) which caused Cursor to steal developer secrets from environment variables and submit them to an attacker's server
-

Cursor AI warns MCP servers present security risks to users
By
–
Apparently @cursor_ai
's official position on MCP is "MCP servers, especially ones that connect to untrusted data sources, present a serious risk to users. We always recommend users review each MCP server before installation and limit to those that access trusted content." -
Colin’s Account Compromised: Cybersecurity Incident Alert
By
–
Can't believe Colin's account got hacked
-
100+ Organizations Launch AI Cybersecurity Education Initiative
By
–
We joined the Pledge to America's Youth along with 100+ organizations committed to advancing AI education. We'll work with educators, students, and communities nationwide to build essential AI and cybersecurity skills for the next generation.
-

Apple’s $600B deal, eye drops tech, and DoorDash milestone
By
–
Top stories in tech today: – Apple’s $600B deal with Trump
– Eye drops to replace reading glasses
– DoorDash rides a $100B high
– WhatsApp removes 6.8M scam accounts
– Quick hits on other major tech news Read more: https://
tech.therundown.ai/p/apples-600b-
tariff-dodge
… -

Confidential Computing: Securing Data During Cloud Processing
By
–
Data encryption has traditionally guarded storage and transmission, but the challenge has always been protecting information during processing. Confidential computing addresses this gap with a precision that reflects the maturity of cloud security today. Microblog @antgrasso