Desk/2025-W39

Week of Sep 22–28, 2025

4 records1 status changes on new evidence0 new findings

What changed in what we know

Attacks & incidents

Sep 25, 2025
Malicious postmark-mcp npm package quietly copied every sent email to an outside address
AttackIncidentKoi Security, Postmark

A package impersonating a Postmark email MCP server was published to npm and, after 15 clean versions, version 1.0.16 (2025-09-17) added code that blind-copied all emails sent through it to the publisher. Postmark stated it had never published an MCP server on npm; Koi Security found it, and the package was deleted after about 1,643 downloads.

Sep 25, 2025
ForcedLeak: Web-to-Lead prompt injection could make Salesforce Agentforce leak CRM data
AttackVulnerability disclosureNoma Security, Salesforce

Noma Security reports that instructions submitted through a public Web-to-Lead form could later steer Agentforce to send CRM data to a domain on Salesforce's allowlist that had expired and could be re-registered. Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 2025-09-08 and re-secured the domain; Noma rates the chain CVSS 9.4.

Defense & research

Policy & standards

Sep 22, 2025
Google DeepMind Frontier Safety Framework v3 retains Cyber Uplift Level 1 critical capability level
PolicyFrameworkGoogle DeepMind

Google DeepMind's Frontier Safety Framework version 3.0 adds a harmful manipulation CCL and expands misalignment and internal-deployment provisions. Its cyber domain keeps a single CCL, Cyber uplift level 1, for models providing sufficient uplift with high-impact cyber attacks to add expected harm at severe scale, paired with Security Level 2; the framework reasons that automated cyber-defense and social adaptation make higher security levels likely unwarranted.