Today's digest · Tuesday, September 29

The 10 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
DEV Community·1 min·4d agoFREE

Malicious MCP Servers: What Deadbugz Taught Us About Auditing Our AI Agent Setup

A DEV Community post titled "Malicious MCP Servers: What Deadbugz Taught Us About Auditing Our AI Agent Setup" discusses auditing AI agent setups in light of malicious MCP servers, referencing something called Deadbugz. The retrieved source text consists almost entirely of injected CSS styling for a DEV Community article page, including theme rules for light and dark modes, and contains no substantive reporting on the incident, the servers involved, or any audit findings.

The source offers only a title about auditing AI agent setups against malicious MCP servers, with no body text to ground developer guidance.

mcpsecurityagentsauditing
dev.to
Malicious MCP Servers: What Deadbugz Taught Us About Auditing Our AI Agent Setup
Over 16,000 Supabase databases expose PII, passwords, auth tokens
#2 / TOP STORY
BleepingComputerFREE

Over 16,000 Supabase databases expose PII, passwords, auth tokens

BleepingComputer reports that more than 16,000 Supabase databases are exposed, with the exposed data including personally identifiable information, passwords, and authentication tokens. The publication attributes the exposure to misconfigured Supabase apps, per its headline and URL slug. The source text provided consists of the article title and a truncated page fragment, so no further details on the affected projects, the configuration involved, or any response are available in the excerpt.

OpenAI exposes “new variety of prompt injection” that can spread like computer worms
#3 / TOP STORY
The New StackFREE

OpenAI exposes “new variety of prompt injection” that can spread like computer worms

OpenAI has disclosed what The New Stack describes as a "new variety of prompt injection" that can spread like computer worms. According to the report, the flaw allows injected instructions to propagate between systems rather than remaining confined to a single prompt or session. The source frames the issue as a distinct class of prompt injection, separate from previously documented single-target attacks. The report ties the disclosure to OpenAI, which exposed the behavior. The source-grounded consequence is that prompt injection can now be described as capable of worm-like spread, a property the article attributes to this newly identified variety.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth knowing7 stories

Developers can benchmark tiny Q4 LLMs locally in the browser via WebGPU, with objective token checks instead of subjective writing-quality judgments.

llmwebgpubrowserbenchmark
Hacker News4d ago1mFREE
// Yesterday1 story