New research and reporting highlight how indirect prompt injection and agent memory can create persistent insider-style risk, while coding agents remain susceptible to prompt-driven unsafe actions. Adjacent cybersecurity updates, including CISA KEV additions and critical flaws in self-hosted platforms, reinforce that classic exploitation paths still underpin most AI compromise scenarios.