Dev.to
7/15/2026

Agent runtime security: Foundry, GitHub, Mastra updates
Short summary
Three agent-runtime security developments: Microsoft Foundry shipped procedural memory, centralized Toolboxes, and a hosted Agent Service for production-grade agent orchestration. A critical prompt-injection vulnerability in GitHub Agentic Workflows allows unauthenticated attackers to embed instructions in public issues that execute with full agent permissions. A Mastra maintainer account was hijacked to inject a typosquatted dependency reaching 28M monthly downloads in a 27-minute window.
- •Microsoft Foundry adds procedural memory, Toolboxes, and hosted Agent Service (public preview)
- •GitHub Agentic Workflows vulnerable to prompt injection via public issues—disable cross-repo access now
- •Mastra supply chain attack: hijacked maintainer injected typosquat dependency reaching 28M downloads in 27 minutes
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



