chiprook
← Security
SecuritySeptember 25, 2026, 18:32

Darktrace: history poisoning turns coding agents into attackers

Darktrace demonstrated a "history poisoning" attack: Claude Code, Codex and Kiro-CLI store conversation history on disk without verifying it came from the model, then read it as trusted context on startup. A malicious package can write a fake dialogue authorizing a network scan, and the agent will execute it after restart. Separately, OX Security analyzed 15,465 public MCP servers: 15.6% resolve outside the US and 0.45% run on home networks.

Darktrace: history poisoning turns coding agents into attackers
#Darktrace#Claude#Codex#MCP
Read next
Security

Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching

Security

Attackers Poison ChatGPT, Gemini and Google AI Overview Answers

Security

AI Coding App ZCode Found Silently Uploading Entire Git History

Security

Codex Desktop flaw let untrusted code read auth tokens from shared memory