Microsoft disclosed and fixed AutoJack on June 18, 2026, after researchers found an AutoGen Studio development-branch exploit chain that could let a malicious webpage trigger code execution through a local MCP WebSocket on the machine running the agent. If you run AutoGen Studio, the practical...