Earlier quoted context omitted.
Have you read the article? The source of the attack is an inbound email received in the logged in user's mailbox and read by the logged in user's Claude Desktop app.
Did you? It beggars belief how stupid this is. Yes, if you hook up your Claude client to an email MCP and a shell MCP then it's like you're piping emails to your shell.
Common? Also, yes.
This one targets Claude. But we've already seen it with Copilot and I expect we'll soon see it hit Gemini, and others.
AI is being forcibly integrated across all major systems. Your email provider will set this up, if they haven't already.