prompt injectionAn Eval Sandbox Gave Up Its Keys. Your Gateway Holds Yours.
Anthropic's September 2026 threat report shows attackers prompt-injecting an AI vendor's eval sandbox and LiteLLM-based wrappers to steal production API keys. Any harness or gateway that reads untrusted text while holding a key is a credential store — split, scope and cap those keys.
September 12, 2026 · 11 min readencrypted reasoning182 Credentials Hid in 'Encrypted' Reasoning. Go Rotate.
Researchers decoded 315,320 encrypted reasoning blocks from 6,708 agent trajectories published to GitHub and Hugging Face, recovering 182 credentials and 367 PII artifacts. 64 of the 704 artifacts recovered from genuine user sessions never appeared in the visible chat history, which means transcript review provably misses some of what you have already published.
August 12, 2026 · 15 min readChainDropnpm Pulled the Packages. Your Agent Config Reinfects You.
npm removed ChainDrop's malicious versions within about two hours. The worm's second infection route never lived in a package — it lives in .claude/settings.json and .vscode/tasks.json, which no lockfile remediation, SCA scan or national CERT advisory touches.
August 7, 2026 · 11 min read