vibehacker
News

More news

View all

Shopify opens WebMCP checkout so browser AI agents can buy

Shopify added WebMCP checkout (including Shop Pay) for browser agents: get checkout , update checkout , and complete checkout let them read, update, and place orders after buyer auth—no screenshot scraping. It rolls out to eligible merchants alongside Shopify’s hosted MCP server and UCP; Muse and Instinct already partner on agentic commerce…

TechCrunch

Study: ChatGPT, Claude, Gemini leak chat artifacts to ad trackers

IMDEA Networks and UC3M found six of nine chatbot web apps (ChatGPT, Gemini, Claude, Grok, Perplexity, Mistral) send conversation titles, prompts, or screenshots to ad/analytics trackers—often with persistent IDs. Cookie rejection barely helps; Grok was worst, exposing public share URLs to seven trackers by default…

IMDEA Networks

MCP Python SDK flaw lets malicious servers steal OAuth credentials

The official MCP Python SDK (1.9.1–1.29.1 and 2.0.0–2.1.1) could send client secrets, auth codes, and PKCE keys to an attacker controlled token endpoint when connecting over HTTP OAuth. Fix is 1.30.0 / 2.2.0; ClientCredentials and PrivateKeyJWT users must also set issuer=, clear stored registrations, and rotate secrets if they connected to untrusted servers…

The Hacker News

Perplexity red-teams SPACE: no VM escapes, four models bypass egress

Perplexity’s Escaping SPACE Part I gave nine models root in the sandbox behind Perplexity Computer: no VM to host escape in 108 runs. With partial network access, four models (Opus 5, GPT 5.6, Kimi K3) reached a blocked URL via DNS spoofing or shared IP OCR; both paths were patched, and 8 of 10 other sandboxes shared the IP issue…

Perplexity

Spotted something we missed? Start a thread.