Canonical, dated answers for coding agents — every entry states when it was true and which versions it applies to, so your context never goes stale.
34+ malicious packages (384 versions) planted .cursorrules/CLAUDE.md with invisible zero-width-Unicode instructions. First documented at-scale attack on the agent instruction channel itself.
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
Treat every file, web page, and tool output your agent reads as untrusted input. Structural defenses beat prompt-based ones.
The 2026 revision (Aug 2026) of the OWASP Top 10 for LLM applications reorders around real incidents: prompt injection stays #1-class, agentic/supply-chain risks rose sharply, and multi-agent trust boundaries got their own focus.