Intelligence category
Agent & Supply Chain Security
Incidents, threat intelligence, prompt injection, identity, cloud, and software supply-chain risk.
- Google CodeMender Moves AI Vulnerability Remediation From Finding to Verified Patch — 2026-07-23
- Kiro Let Web Prompt Injection Rewrite Its MCP Config and Execute Code — 2026-07-23
- Hidden Pull-Request Text Can Turn Azure DevOps MCP Review Agents into Confused Deputies — 2026-07-22
- FakeGit Turns AI Capability Discovery Into a Malware Delivery Channel — 2026-07-22
- OpenAI’s Cyber Evaluation Escaped Its Sandbox and Breached Hugging Face — 2026-07-22
- Hugging Face Says an Autonomous Agent Breached Its Dataset Pipeline — 2026-07-17
- Grok Build 0.2.93 Uploaded Whole Git Repositories Before Server-Side Shutdown — 2026-07-14
- Cloudflare Precursor Moves Agent Detection From Requests to Full Sessions — 2026-07-13
- Ghostcommit Hides Secret-Theft Instructions in Images AI Code Reviewers Never Open — 2026-07-13
- AWS MCP Gateway Registry SQL Injection Exposes API Key Material — CVE-2026-14471 — 2026-07-12
- Google Cloud Run Sandboxes Put Agent-Generated Code Behind Deny-by-Default Egress — 2026-07-12
- Ethereum Foundation AI Agent Audit — CVE-2026-34219 Gossipsub DoS — 2026-07-11
- Microsoft — Claude Code GitHub Action Exposes CI/CD Secrets via /proc/self/environ — 2026-07-11
- Microsoft MDASH — AI Agentic Scanning Finds 16 Windows CVEs in First Run — 2026-07-11
- OpenClaw AI Agent — WhatsApp Message to Host RCE via Sandbox Bypass — 2026-07-11
- CrowdStrike Prompt Injection Taxonomy — 200+ Techniques Cataloged — 2026-07-10
- CISA — Langflow Becomes First AI Agent Platform in KEV Catalog (CVE-2026-55255) — 2026-07-09
- arXiv — GitHub Copilot Refuses Harmful Requests in Chat, Writes Them in Code — 2026-07-09
- ESET — 3,000+ Malicious AI Skills Found in Agent Ecosystem Scan — 2026-07-09
- European Commission — EU Action Plan on Cybersecurity and AI — 2026-07-09
- Fiddler AI — AI Coding Agent Threat Models and Controls — 2026-07-09
- When Your Software Supply Chain Includes AI Writing Your Code — 2026-07-09
- Sygnia — Lone Attacker Uses Agentic AI to Compromise AWS in 72 Hours — 2026-07-09
- TeamPCP — Supply Chain Compromise of Trivy, LiteLLM, and KICS Feeds VECT Ransomware Credential Archive — 2026-07-09
- GitLost — GitHub Agentic Workflows Leak Private Repos via Prompt Injection — 2026-07-08
- Zscaler — Indirect Prompt Injection Tricks AI Agents Into Crypto Payments — 2026-07-08
- AI Bug Hunting Drives Record CVE Spike — 1,500 High-Severity Flaws in June 2026 — 2026-07-07
- FatFs: LLM-Assisted Fuzzing Finds 7 CVEs in Embedded Firmware — 2026-07-07
- Microsoft Execution Containers (MXC) — Sandboxing AI Agents on Windows — 2026-07-07
- NVIDIA Releases SkillSpector — Open-Source Scanner for AI Agent Skills — 2026-07-07
- TrendAI Audit Finds 4,982 Security Flaws Across 2,259 Public MCP Servers — 2026-07-07
- Vercel Breach: Shadow AI Tool Becomes Identity-Based Supply Chain Pivot — 2026-07-07
- Adversa AI — 27 Agentic AI Security Resources for July 2026 — 2026-07-06
- Check Point — Critical Vulnerability Exposures Double in 2026, AI-Driven Triage Urgent — 2026-07-06
- China — AI Companion Regulation Forces ByteDance and Alibaba to Kill Agent Features — 2026-07-06
- CMU — FLARE-AI Open-Source Platform for Cross-Platform AI Vulnerability Reporting — 2026-07-06
- Microsoft — CVE-2026-41106 Copilot Cross-Tenant Privilege Escalation — 2026-07-06
- Tencent AI-Infra-Guard — Multi-Layer Agent Red Teaming Framework — 2026-07-05
- arXiv — SkillCloak Bypasses 90%+ of Agent Skill Scanners With Payload-Preserving Evasion — 2026-07-05
- AvePoint: 88% of Organizations Report AI Agent Security Breaches as Visibility Gaps Triple — 2026-07-05
- T3MP3ST — Open-Source Framework Turns AI Coding Agents Into Autonomous Red Teamers — 2026-07-05
- CVE-2026-52830 — fast-mcp-telegram Path Traversal Bypasses Session Protection — 2026-07-04
- DataDome — AI Agent Identity Crisis Drives H1 2026 Threat Landscape — 2026-07-04
- Unit 42 — Malicious OpenClaw Skills on ClawHub Delivered Infostealers and Crypto Fraud — 2026-07-04
- Alibaba Bans Claude Code Over Alleged Covert Environment Detection — 2026-07-03
- NVIDIA — Fine-Tuned 30B Model Outperforms Frontier LLMs at Agent Exploitation — 2026-07-03
- Flowise CVE-2026-40933 — MCP stdio Transport RCE on Import — 2026-07-03
- LiteLLM PyPI Supply Chain Attack — Credential Stealer in Versions 1.82.7–1.82.8 — 2026-07-03
- Mozilla 0DIN — Claude Code DNS Reverse Shell Attack via Poisoned Repository — 2026-07-03
- Pentera — Claude Desktop Turned Into Double Agent via Personalization Sync — 2026-07-03
- TOCTOU Attack Tricks AI Computer-Use Agents Into Clicking the Wrong Thing — 2026-07-03
- Cursor — DuneSlide: Two Zero-Click RCEs Let Prompt Injection Escape the Sandbox — 2026-07-02
- Sysdig JADEPUFFER — First Documented Agentic Ransomware Operation — 2026-07-02
- Socket — AI Coding Agents Are the Supply Chain Blind Spot Nobody Mapped — 2026-07-02
- Adversa AI — GuardFall: Decades-Old Bash Tricks Bypass Shell Guards in 10 of 11 AI Coding Agents — 2026-07-01
- Anthropic — Claude Fable 5 Returns With Industry Jailbreak Framework After Export Controls Lifted — 2026-07-01
- Apple — Accelerated Security Updates in Response to AI-Powered Threats — 2026-07-01
- LayerX — BioShocking: AI Browser Guardrail Bypass via Fictional Context Manipulation — 2026-07-01
- Adversa AI — GuardFall: Bash Tricks Bypass Safeguards in 10 of 11 AI Coding Agents — 2026-07-01
- Microsoft — Poisoned MCP Tool Descriptions Make AI Agents Silently Exfiltrate Company Data — 2026-07-01
- Unit 42 — Phantom Squatting: Attackers Weaponize AI-Hallucinated Domains for Phishing and Malware — 2026-07-01
- Djinn Stealer — SimpleHelp CVE-2026-48558 Exploit Targets MCP Configs and AI Dev Credentials — 2026-06-30
- MCP Protocol Rewrite — Session IDs Removed, Security Decisions Shifted to Developers — 2026-06-30
- Mini Shai-Hulud Worm — 170+ npm and PyPI Packages Compromised in Self-Replicating AI Supply Chain Attack — 2026-06-30
- PromptSnatcher — Chrome Ad-Blockers Secretly Intercepting AI Chats — 2026-06-30
- Rapid7 — Modernizing Vulnerability Standards for the AI Era — 2026-06-30
- Wake Forest — 282 iOS AI Apps Leak LLM API Keys in Network Traffic — 2026-06-30
- Forbes — Gartner Tells CISOs to Block All AI Browsers as Prompt Injection Defenses Fail — 2026-06-29
- Miasma — LeoPlatform Supply Chain Attack Expands to Go, Targets AI Coding Assistants — 2026-06-29
- Mitiga — Poisoned Coding Test Turns AI Agent Into Attacker, 1,230+ Repos Leaking API Keys — 2026-06-29
- Mozilla 0DIN — Clean GitHub Repo Delivers Reverse Shell via AI Coding Agents — 2026-06-29
- VentureBeat — Prompt Injection Exploits Enterprise AI Design Flaws Across Agents, RAG, and Model Routers — 2026-06-29
- Microsoft — AutoJack RCE chain hijacks AutoGen Studio agents via MCP WebSocket — 2026-06-28
- Black Hat 2026 — First Copilot Sandbox Escape, AI Agent Exploitation & Offensive Models — 2026-06-28
- Microsoft — The state of MCP security in 2026: OAuth, supply chain, and shadow servers — 2026-06-28
- BioShocking — LayerX Breaks Guardrails in Six AI Browsers via Context Manipulation — 2026-06-27
- DevFortress — The 2026 AI Agent Credential Crisis: 28M Secrets, 200K Vulnerable Servers — 2026-06-27
- MCP 2026-07-28 Specification — Akamai Maps New Attack Surfaces After Security Overhaul — 2026-06-27
- OpenAI — GPT-5.6 Sol Restricted to Government-Approved Users After White House Cyber Review — 2026-06-27
- Unit 42 — ClawHub Evasive Skills Deploy Infostealers and Agentic Financial Fraud — 2026-06-27
- AIR — Malicious AI Agent Skill Bypassed Cisco, NVIDIA Scanners, Reached 26,000 Users — 2026-06-26
- Amazon Q Developer — Malicious Repo MCP Config Steals Cloud Credentials (CVE-2026-12957) — 2026-06-26
- Huntress — EvilTokens AI PhaaS Platform Drives 1,380% Surge in Device Code Phishing — 2026-06-26
- SentinelOne — macOS.Gaslight: North Korean Implant Uses Prompt Injection to Blind AI Triage — 2026-06-26
- OWASP — Agentic Skills Top 10: First Security Framework for AI Agent Skill Ecosystems — 2026-06-26
- PixelSmash (CVE-2026-8461) — FFmpeg RCE Hits vLLM and AI Video Pipelines — 2026-06-26
- Zentera MCP Security Enterprise Guide — Model-Directed Tool Calls Expand Attack Surface — 2026-06-26
- curl 8.21.0 — AI-Powered AISLE Platform Finds 6 CVEs Including 25-Year-Old mTLS Flaw in Record Release — 2026-06-25
- DeepMind AI Control Roadmap — Defense-in-Depth for Securing AI Agents — 2026-06-25
- AIR — Fake AI Agent Skill Bypassed All Scanners, Reached 26,000 Agents — 2026-06-24
- Cordyceps CI/CD Flaw Exposes Google AI Agent Kit, Microsoft, Apache Repos — 2026-06-24
- DifyTap — Four CVEs Expose Cross-Tenant AI Chats on 1M+ App Platform — 2026-06-24
- OpenAI Daybreak — GPT-5.5-Cyber and Codex Security Plugin for Vulnerability Patching — 2026-06-24
- OWASP MCP Top 10 — First Protocol-Specific AI Agent Risk Framework — 2026-06-24
- pgAdmin AI Assistant Bypass Enables RCE via Prompt Injection — 2026-06-24
- Cyberpress — 23 ClawHub Plugins Found Impersonating Official @openclaw and @clawhub Namespaces — 2026-06-23
- JetBrains IDE Plugins — 15 Malicious Add-ons Caught Stealing AI API Keys — 2026-06-23
- SecurityWeek — North Korean Sapphire Sleet Hits 140+ Mastra AI Agent Packages in NPM Supply Chain Attack — 2026-06-23
- Open WebUI CVE Cluster — Auth Bypass, Data Exposure, and Path Traversal — 2026-06-23
- OrcaRouter — AI Threat Report 2026 and Free Agent Firewall for Prompt Injection Defense — 2026-06-23
- MCP Ecosystem — 973 Packages, 71% Single-Maintainer, Early-npm-era Supply Chain Maturity — 2026-06-23
- SpecterOps — SQL Server 2025 AI Features Weaponized for Data Exfiltration and C2 — 2026-06-23
- Tenet Security — Agentjacking Attacks Hijack AI Coding Agents via MCP — 2026-06-12
- Phoenix Security — 59 supply-chain campaigns, zero CVEs, AI tooling as new attack surface — 2026-06-12
- Socket — Shai-Hulud Wave 2 Targets MCP and Bioinformatics PyPI Developers — 2026-06-12
- Brave Research — Indirect Prompt Injection Hits Mozilla Tabstack and Cotypist — 2026-06-11
- Meta AI Chatbot — 20,000+ Instagram Account Takeovers — 2026-06-11
- Microsoft — Seven New AI Agent Attack Vectors in Failure Taxonomy — 2026-06-11
- Varonis — OpenClaw Agent Phishing Simulation Exposes Cloud Credentials — 2026-06-11
- Anthropic — Claude Fable 5 and Mythos 5 Launch with Cybersecurity Guardrails — 2026-06-10
- CISA Adds CVE-2026-42271 to KEV — LiteLLM Active Exploitation Confirmed — 2026-06-10
- The Register — Miasma Supply-Chain Attack Toolkit Open-Sourced on GitHub — 2026-06-10
- Check Point — IKEv1 VPN Auth Bypass (CVE-2026-50751) Exploited by Qilin Ransomware — 2026-06-09
- Claude Code MCP Token Theft — npm Package MITM — 2026-06-09
- Docker — AI Coding Agent Horror Stories: Filesystem Destruction Risk — 2026-06-09
- Google Sites — Fake Claude Code and Codex Installer Phishing Campaign — 2026-06-09
- depthfirst AI Agent Finds 21 FFmpeg Zero-Days — 2026-06-09
- LiteLLM PyPI Supply-Chain Attack — Malicious Versions 1.82.7 & 1.82.8 Published Directly to PyPI — 2026-06-09
- NVIDIA — SkillSpector Open-Source Scanner for AI Agent Skills — 2026-06-09
- Shai-Hulud — Hades Branch Poisons 23 PyPI Packages Targeting MCP Developers — 2026-06-09
- Anthropic — Project Glasswing Expands Mythos Preview to 200 Organizations, 10,000+ Vulnerabilities Found — 2026-06-08
- OWASP — CVE Lite CLI Brings AI Agent Integration to Local-First Vulnerability Scanning — 2026-06-08
- Picus Security — CVE Weaponization Time Collapses to 24 Hours in 2026 — 2026-06-08
- Sysdig — Agentic Threat Actor Performs Container Escape and Kubernetes Credential Replay — 2026-06-08
- LLMjacking: Five Routes Attackers Use to Steal Inference — 2026-06-07
- Miasma npm Worm Hits 57 Packages via binding.gyp — 2026-06-07
- Microsoft — Framework CVEs: Prompt Injection to RCE Across Semantic Kernel, CrewAI, LangChain — 2026-06-07
- NSA Issues MCP Security Guidance for AI Agent Protocol — 2026-06-07
- Nx Console VS Code Extension — Poisoned Extension Breaches 3,800 GitHub Internal Repos — 2026-06-07
- OpenAI — ChatGPT Lockdown Mode to Block Prompt-Injection Exfiltration — 2026-06-07
- Sophos X-Ops — Threat Actors Use AI Coding Agents to Build EDR Evasion Frameworks — 2026-06-07
- Trail of Bits Bypasses ClawHub, Cisco & Vercel AI Skill Scanners — 2026-06-07
- Adversa AI — Coding Agent RCE Roundup: SymJack, TrustFall, Copirate 365 — 2026-06-06
- RyotaK — Claude Code GitHub Actions Supply Chain Compromise via Permission Bypass — 2026-06-06
- CloudSEK AIVigil — Unauthenticated MCP Server Led to SSRF and AWS Credential Theft — 2026-06-06
- HTTP/2 Bomb — OpenAI Codex Chains Decade-Old DoS Into Web Server Crash — 2026-06-06
- JFrog — IronWorm: Rust-Based npm Worm with eBPF Rootkit Targets AI/Dev Tooling — 2026-06-06
- Kiteworks — The Lethal Trifecta: Why Most AI Agents Are Structurally Exploitable — 2026-06-06
- Miasma Worm Targets AI Coding Agents via GitHub Repo Config Injection — 2026-06-06
- Microsoft — Updated Agentic AI Failure Modes Taxonomy (7 New) — 2026-06-06
- Adversa SymJack — Symlink-Hijack RCE in AI Coding Agents — 2026-06-06
- VIPER-MCP Scans 40,000 Repos, Finds 106 Zero-Days in MCP Servers — 2026-06-06
- GitGuardian MCP Governance Framework for Enterprise AI — 2026-06-05
- Exposed MCP Servers Triple to 1,467; Trend Micro Finds Cloud Command-Injection Flaws — 2026-06-05
- Meta AI Support Bot — Instagram Account Takeover via Prompt Injection — 2026-06-05
- AIRQ Report — Only 11% of Production Agents Pass AI Security Bar — 2026-06-04
- Anthropic Opus 4.8 Browser Agent — 31.5% Pre-Safeguard Hijack Rate — 2026-06-04
- Claroty Team82 — LLMs Discover Critical ICS Vulnerabilities Without Prior Disclosures — 2026-06-04
- Four Major AI Labs Use Incompatible Prompt-Injection Metrics — 2026-06-04
- LibreChat CVE-2026-32625 — MCP URL Env-Var Interpolation Leaks Secrets — 2026-06-04
- Microsoft — Dependency Confusion npm Packages Profile Developer Environments — 2026-06-04
- LibreChat MCP Credential Exfiltration (CVE-2026-44653/44654) — 2026-06-03
- Microsoft Build 2026 — Enterprise Agent Security with MDASH and Purview — 2026-06-03
- Palo Alto Networks CVE-2026-0257 — Active Exploitation of GlobalProtect Auth Bypass — 2026-06-03
- Palo Alto Unit 42 — Red Hat npm Supply Chain Attack and Miasma Malware — 2026-06-03
- Permiseo — ChatGPhish Browser-Based Prompt Injection — 2026-06-02
- Cisco AI Defense launches agent-security tooling suite — 2026-06-02
- Push Security — LLMShare Campaign Abuses ChatGPT & Claude Share Links for Malware — 2026-06-02
- Wiz — Miasma Supply Chain Attack on Red Hat npm Packages — 2026-06-02
- NSA — MCP Security Guidance Warns AI Agent Protocol Adoption Outpaced Security — 2026-06-02
- Aikido — OpenAI Codex Token Theft via codexui-android npm Package — 2026-06-02
- Salt Security — 90% of security leaders worried about AI-generated code risks — 2026-06-02
- Copirate 365 — DEF CON Demo of Persistent Microsoft Copilot Backdoor — 2026-06-01
- DeepMind — 32% Surge in Malicious Prompt Injections Targets Payment Agents — 2026-06-01
- Halborn — Mercor Lost 4 TB via LiteLLM Supply-Chain Breach — 2026-06-01
- Microsoft — Typosquatted npm Packages Steal Cloud & CI/CD Secrets — 2026-06-01
- OpenAI TAC — passkey mandate for cyber-capable model access — 2026-06-01
- Startup Fortune — vLLM and MCP Server Flaws Turn AI Infrastructure Into Supply-Chain Risk — 2026-06-01
- FBI — Kali365 AI Phishing-as-a-Service Bypasses MFA via OAuth Device Codes — 2026-05-31
- Memory Poisoning — The New Attack Surface That Beats Prompt-Injection Defenses — 2026-05-31
- Okta AI Agents — Identity Sprawl and the Rogue Agent Kill Switch — 2026-05-31
- OWASP — Agent Memory Guard, a Runtime Defense Against Memory Poisoning — 2026-05-31
- Pentest Swarm — AI Autonomous Penetration Testing Tool with MCP Server — 2026-05-31
- CERT-In — 12-hour patch mandate calibrated to AI exploitation speed — 2026-05-30
- Permiso — ChatGPhish Turns ChatGPT Summaries Into a Phishing Surface — 2026-05-30
- Detectify — MCP Server brings deterministic vuln scanning into AI coding agents — 2026-05-30
- Obsidian — Flowise CVE-2026-40933 MCP stdio Supply-Chain RCE — 2026-05-30
- Geordie — $30M Series A for AI Agent Security and Governance — 2026-05-30
- WithSecure — GreyVibe Russia-Linked Group Supercharges Ops with AI — 2026-05-30
- Push Security — LLMShare Campaign Abuses ChatGPT Sharing to Deliver Malware — 2026-05-30
- Flashpoint — Deepfake KYC Bypass Kits Sold as SaaS to Criminals — 2026-05-29
- JFrog — 2026 Supply Chain Report: npm Attacks Up 451%, 495 Malicious AI Models — 2026-05-29
- jqwik Maintainer Sneaks Data-Nuking Prompt Injection Into AI Coding Agents — 2026-05-29
- Sysdig: First LLM Agent-Driven Intrusion via Marimo CVE-2026-39987 — 2026-05-29
- UVCyber MCP Threat Advisory: 40+ CVEs, Tool Poisoning, and the Missing Auth Layer — 2026-05-29
- Cogent — AI exploit dev shrinks weaponization from 125 days to 12 hours — 2026-05-28
- Check Point — AI Attacks Go Mainstream: Single Operator Breached 9 Mexican Agencies Using AI Orchestration — 2026-05-28
- GlassWorm — developer-targeting botnet takedown (CrowdStrike, Google) — 2026-05-28
- TechRepublic / TechTimes — The AI Agent Governance Gap: 88% of Deployments Already Breached — 2026-05-28
- Megalodon — Mass GitHub CI/CD Supply Chain Attack Hits 5,561 Repos — 2026-05-28
- Perplexity Bumblebee — Open-Source Scanner for Dev Endpoints and MCP Configs — 2026-05-28
- Starlette CVE-2026-48710 "BadHost" — FastAPI AI Infrastructure Exposed — 2026-05-28
- Adversa AI — SymJack symlink-to-RCE via AI coding agents — 2026-05-28
- Trend Micro "Return-to-Tool" — AI Agents as Attack Chains — 2026-05-28
- Anthropic Claude Code Security-Guidance Plugin — Three-Layer In-Session Vulnerability Detection — 2026-05-27
- Check Point — IRGC-linked group uses AI-assisted MiniFast malware — 2026-05-27
- Oasis Security — Claudy Day: Claude.ai Prompt Injection to Silent Data Exfiltration — 2026-05-27
- Paubox — Invisible text prompt injection bypasses AI email filters — 2026-05-27
- PromptArmor — Copilot Cowork Prompt Injection Bypasses M365 Approval to Exfiltrate Files — 2026-05-27
- CSO: Treat AI Models as Untrusted Components, Google and UCSD Researchers Argue — 2026-05-26
- AudioHijack — Hidden-Audio Prompt Injection Targets Voice AI — 2026-05-26
- Consensus MCP Tool — Hidden Ad Injection in Claude Instructions — 2026-05-26
- Mitiga Breaking Skills — AI Agent Skills Enable Silent Codebase Exfiltration — 2026-05-26
- Microsoft Releases Agent Governance Toolkit — Policy Enforcement for AI Agents — 2026-05-25
- NSA Releases MCP Security Design Considerations for AI-Driven Automation — 2026-05-25
- Cybersecurity Insiders — Three Prompt Injection Detection Blind Spots — 2026-05-25
- TrapDoor Supply Chain — .cursorrules and CLAUDE.md Hijack AI Assistants — 2026-05-25
- 1Password + OpenAI — Just-in-Time Credentials for Codex Agents — 2026-05-24
- Adaptive Security — 80% of employees use unapproved AI tools, 12% of companies govern them — 2026-05-24
- Aikido Security — Laravel-Lang supply chain delivers cross-platform credential stealer — 2026-05-24
- NVIDIA OpenShell — open-source secure sandboxed runtime for AI agents — 2026-05-24
- Google Threat Intel — LLM-Generated Morphing Malware and Automated Vulnerability Discovery — 2026-05-23
- TeamPCP — 20-Wave Supply-Chain Campaign Hits 500+ Tools, GitHub — 2026-05-23
- WordPress 7.0 — AI Agent Infrastructure and API Key Theft Risk — 2026-05-23
- CSA Research Note: MCP Security Crisis — Systemic Design Flaws in AI Agent Infrastructure — 2026-05-22
- Pydantic AI — SSRF Cloud-Metadata Blocklist Bypass via IPv6 — 2026-05-22
- Spring AI MCP — SSRF via Dynamic Client Registration — 2026-05-22
- Microsoft Defender Guide — Memory Poisoning, Jailbreaks, Evasion for AI Agents — 2026-05-21
- Microsoft Open-Sources RAMPART and Clarity for AI Agent Security — 2026-05-21
- Verizon DBIR 2026 — Exploitation Tops Credential Abuse, AI Shrinks Defense Windows — 2026-05-21
- GitHub Breach — Poisoned VS Code Extension Exfiltrates 3,800 Internal Repos — 2026-05-20
- Mini Shai-Hulud — Malware Persists via Claude Code Hooks and VS Code Auto-run Tasks — 2026-05-20
- SentinelOne — Prompt for Agentic AI Security: MCP Discovery and Runtime Governance — 2026-05-20
- Sysdig: Runtime Security Is the Missing Layer in Agentic AI Tooling — 2026-05-20
- TeamPCP Poisons Microsoft durabletask PyPI Package — 2026-05-20
- Discourse — CVE-2026-32244 Cached AI Summaries Leak Removed Content — 2026-05-19
- Forcepoint — TeamPCP Turns LiteLLM into a Credential Stealer — 2026-05-19
- Lasso Security — Open-Source Claude Code Prompt Injection Defender — 2026-05-19
- NVIDIA Vera CPU — First Deliveries to Anthropic, OpenAI, Oracle for Agentic AI Infrastructure — 2026-05-19
- OX Security — First Shai-Hulud Clones Hit npm with DDoS Botnet — 2026-05-19
- Truffle Security — Claude Coding Agent Autonomously Exploited SQL Injection Across 30 Companies — 2026-05-19
- Wiz — TeamPCP Hits @antv npm Namespace, GitHub Actions, and VSCode — 2026-05-19
- Linus Torvalds — AI Bug Reports Overwhelm Linux Security Mailing List — 2026-05-18
- MCPSafe — 7 Coordinated Disclosures After Scanning 50+ MCP Servers — 2026-05-18
- OpenClaw Five-Point Security Plan — fs-safe, Proxyline, ClawHub Ratings — 2026-05-18
- Pwn2Own Berlin 2026 — OpenAI Codex Exploited, $1.29M in 47 Zero-Days — 2026-05-18
- Cymulate — Prompt Injection Triggers Zero-Click RCE in AI CLI Tools (Cursor, Kiro, Codex, Gemini) — 2026-05-17
- EU CRA — Vulnerability Reporting Obligations for AI Vendors Begin September 2026 — 2026-05-17
- Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads Targeting AI Agents — 2026-05-17
- MCP Database Flaws — Apache Doris, Pinot and Alibaba RDS Vulnerabilities — 2026-05-17
- Hunt.io — TeamPCP FIRESCALE Malware Uses GitHub Dead-Drop for C2 Resilience — 2026-05-17
- VectorSmuggle — Steganographic Data Exfiltration Through AI Embeddings — 2026-05-17
- HackerOne — Prompt Injection Reports Surge 540% Year-over-Year — 2026-05-16
- Next.js CVE-2026-44578 — WebSocket SSRF Threatens AI-Generated Web Apps — 2026-05-16
- NVIDIA Red Team — Indirect AGENTS.md Injection via Malicious Dependencies — 2026-05-16
- TeamPCP — Hackers Offer Stolen Mistral AI Source Code for $25K on BreachForums — 2026-05-16
- TeamPCP — Shai-Hulud Worm Source Code Open-Sourced, BreachForums Contest Launched — 2026-05-16
- Calif — Researchers Bypass macOS Memory Integrity Enforcement Using Mythos AI — 2026-05-15
- Langflow CVE-2026-33017 Exploited in the Wild — Attackers Steal AWS Keys, Deploy NATS Botnet — 2026-05-15
- Microsoft — Exploitable Misconfigurations in AI Apps, MCP Servers & Mage AI — 2026-05-15
- Socket & StepSecurity — Malicious node-ipc npm Packages Steal Claude AI, Kiro IDE Credentials — 2026-05-15
- OpenAI Breached in TanStack Supply Chain — Code-Signing Certificates Rotated, macOS Users Must Update — 2026-05-15
- Cisco — Foundry Security Spec Open-Sources Agentic AI Security Architecture — 2026-05-14
- CrewAI — Four CVEs Chain Sandbox Escape to Cloud Takeover (VU#221883) — 2026-05-14
- CVE-2026-44246 — nnUNet GitHub Issue Triage Agent Vulnerable to Prompt Injection — 2026-05-14
- The Register — Three MCP Database Server Flaws Discovered, One Unpatched — 2026-05-14
- Microsoft — MDASH Agentic System Finds 16 Windows Flaws Including 4 Critical RCEs — 2026-05-14
- OpenAI — Daybreak Initiative Expands Codex Security Into Enterprise Cybersecurity Platform — 2026-05-14
- Palo Alto Networks — AI Models Drive Majority of Findings in May Patch Cycle — 2026-05-14
- Adversa AI TrustFall — Claude Code One-Click RCE — 2026-05-13
- Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads — 2026-05-13
- JunoClaw — Critical Mnemonic Exposure in Agentic AI Platform (CVE-2026-43992) — 2026-05-13
- Langflow — Path Traversal in Knowledge Bases API (CVE-2026-42048) — 2026-05-13
- Microsoft 365 Copilot — Three Critical Info Disclosure CVEs Patched — 2026-05-13
- Miggo Security — Anthropic, Google, Microsoft Paid Bug Bounties for AI Agent Hijacks, No CVEs Issued — 2026-05-13
- Mini Shai-Hulud — Self-Spreading Supply Chain Worm Hits 169 npm Packages, Mistral AI and UiPath — 2026-05-13
- OWASP MCP Top 10 — 38% of MCP Servers Have No Authentication, 30+ CVEs in 60 Days — 2026-05-12
- Slopsquatting — LLM-Hallucinated Package Names Create New Supply Chain Attack Vector — 2026-05-12
- TeamPCP — Re-Compromises Checkmarx Jenkins AST Plugin Weeks After Initial Breach — 2026-05-12
- Acronis TRU: 575+ Malicious AI Skills on ClawHub and Hugging Face Deploy Malware — 2026-05-11
- ClaudeBleed: Chrome Extension Flaw Allows AI Agent Takeover via Prompt Injection — 2026-05-11
- Five Eyes — Joint Guidance Warns Agentic AI Is Too Dangerous for Rapid Rollout — 2026-05-11
- Grok/Bankrbot Morse Code Prompt Injection Drains $150K Crypto Wallet — 2026-05-11
- SecurityScorecard — Tens of Thousands of Exposed OpenClaw Instances, 35% RCE-vulnerable — 2026-05-11
- ThreatLabz — Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader — 2026-05-11
- VentureBeat — AI Tool Poisoning Exposes the Behavioral Integrity Gap in Agent Registries — 2026-05-11
- Oasis Security — Cline Kanban WebSocket Hijack (CVSS 9.7) — 2026-05-10
- Dragos & Gambit — AI-Assisted OT Intrusion Against Mexican Water Utility — 2026-05-10
- Anthropic — Fed Chair and Treasury Convene Bank CEOs Over Mythos Cyber Risk — 2026-05-10
- Pillar Security — Gemini CLI "TrustIssues" CVSS 10 Supply-Chain Compromise — 2026-05-10
- Postiz CVE-2026-42298 — "Pwn Request" RCE in AI Social Media Scheduler via GitHub Actions — 2026-05-10
- RSAC 2026 — Agent Identity Gap: When Valid Credentials Are Not Enough — 2026-05-10
- VentureBeat — CLI-Anything AI Agent Skill Backdoor and Structural Supply-Chain Gap — 2026-05-10
- Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads Targeting AI Agents — 2026-05-09
- MCPwn — First Named MCP Exploit Campaigns with Actively Exploited CVEs — 2026-05-09
- Vercel Breached via Context AI Supply Chain — Internal Database Sold for $2M — 2026-05-09
- SentinelLabs — PCPJack Cloud Worm Steals AI API Keys, Evicts TeamPCP — 2026-05-08
- Elastic Security — TCLBanker Banking Trojan Distributed via Trojanized AI Prompt Builder — 2026-05-08
- SecurityWeek — Critical Ollama CVE-2026-7482 Exposes 300K Deployments — 2026-05-07
- Sophos — Fake Claude AI Website Delivers Beagle Windows Backdoor — 2026-05-07
- Keep Aware — Browser DLP Blind Spot Lets Sensitive Data Leak to AI Prompts — 2026-05-07
- pnpm 11 — Default Supply Chain Protections Against Malicious Package Installs — 2026-05-07
- Bluekit — Phishing Kit Ships with AI Assistant, Voice Cloning, and 40+ Templates — 2026-05-06
- Material Security — Persistent OAuth Grants and AI Tool Proliferation — 2026-05-06
- Material Security — Unmanaged OAuth Grants from AI Tools Create Persistent Attack Surface — 2026-05-06
- NIST CAISI — Pre-Deployment Testing of Frontier AI Models for Cybersecurity Risks — 2026-05-06
- Palo Alto Networks — CVE-2026-0300 PAN-OS Firewall Zero-Day Actively Exploited — 2026-05-06
- ProjectDiscovery — AI Code Deluge Overwhelms Security Teams — 2026-05-06
- Trend Micro — Quasar Linux Implant Targets Developer and DevOps Environments — 2026-05-06
- Chrome 148 — On-Device AI Model Installed Silently, Exposed to Any Webpage via Prompt API — 2026-05-05
- Computer Use — Vision Agents Cost 45x More Than Structured APIs — 2026-05-05
- Google — Bug Bounty Programs Restructured for the AI Era — 2026-05-05
- NVIDIA NVFlare CVE-2026-24178 — Critical Auth Bypass in Federated ML Training — 2026-05-04
- Proofpoint 2026 AI and Human Risk Landscape — Half of Orgs Hit by AI Incidents — 2026-05-04
- CIS Extends Security Controls to AI Agents and MCP — 2026-05-03
- Oasis Security — "Claudy Day" Prompt Injection and Data Exfiltration Chain in Claude.ai — 2026-05-03
- Novee — CVE-2026-26268 AI Coding Agent RCE in Cursor IDE — 2026-05-03
- OX Security — MCP STDIO Systemic RCE Flaw Affecting 200K AI Agent Servers — 2026-05-03
- OpenAI Pushes Frontier AI Models Into Government Cyber Defense — 2026-05-03
- PromptMink — North Korean-Linked Supply Chain Attack Uses Claude Opus to Plant Malware — 2026-05-03
- Microsoft — Frontier AI Accelerates Vuln Discovery, Calls for Faster Patching & Responsible Release — 2026-05-02
- Palo Alto Networks to Acquire Portkey AI Gateway — 2026-05-02
- Anthropic — Claude Security Public Beta for Vulnerability Scanning — 2026-05-01
- Bishop Fox — AIMap Open-Source AI Infrastructure Scanner — 2026-05-01
- BufferZoneCorp — Poisoned Ruby Gems & Go Modules Target CI Pipelines — 2026-05-01
- CISA & Five Eyes — Joint Guidance on Secure Agentic AI Deployment — 2026-05-01
- Linux Kernel "Copy Fail" — 732-Byte Local Root Exploit Hits Every Major Distro Since 2017 (CVE-2026-31431) — 2026-05-01
- n8n-mcp — SSRF Bypass via IPv4-Mapped IPv6 Addresses (CVE-2026-42349) — 2026-05-01
- PyTorch Lightning — PyPI Package Compromised in Mini Shai-Hulud Supply Chain Attack — 2026-05-01
- VentureBeat — Six Exploits Against AI Coding Agents, All Targeting Credentials — 2026-05-01
- Cequence Security — Agent Personas for Scoped MCP Privileges — 2026-04-30
- TeamPCP Escalates Mini Shai-Hulud Campaign to SAP npm and PyTorch Lightning — 2026-04-30
- NSFOCUS — AI-Scan Security Scanner for OpenClaw Ecosystem — 2026-04-30
- SecureAuth — Agent Trust Registry Opens to the Public for AI Agent Governance — 2026-04-30
- Wiz — Red Agent, AI-BOM, and Wiz Code Expand AI Application Security Platform — 2026-04-30
- ARMO — Why AI Supply Chain Scanning Misses Half the Risk — 2026-04-29
- Lufsec — Model Context Protocol: 4 Trust Boundaries Attackers Are Exploiting — 2026-04-29
- DPRK PromptMink — Claude Opus Used to Insert Malicious npm Dependency — 2026-04-29
- Hugging Face LeRobot — Critical Pickle Deserialization RCE (CVE-2026-25874) — 2026-04-29
- Pipecat Voice Agent Framework — Pickle Deserialization RCE (CVE-2025-62373) — 2026-04-29
- TeamPCP — Claude Code Used to Publish Malicious SAP CAP npm Packages — 2026-04-29
- Cisco — Claude Code memory poisoning enables persistent agent compromise — 2026-04-28
- Cursor AI Agent Deletes PocketOS Production Database in 9 Seconds — 2026-04-28
- vanna-ai — CVE-2026-6977 Improper Authorization in Legacy Flask API — 2026-04-28
- Bitwarden CLI Compromised — Shai-Hulud Campaign Targets AI Coding Assistants — 2026-04-27
- Google — 32% Rise in Indirect Prompt Injection Attacks Found Across Public Web — 2026-04-27
- OpenAI GPT-5.5 Launches With Agentic Safeguard Delays and Bio Bug Bounty — 2026-04-27
- OpenClaw — Three Flaws Enable Policy Bypass and API Credential Theft — 2026-04-27
- Vercel Breach Traced to Lumma Stealer via Roblox Cheats, CEO Cites AI-Accelerated Attackers — 2026-04-27
- The DFIR Report — Bissa Scanner: AI-Assisted Mass Exploitation — 2026-04-26
- CrowdStrike — 90+ Organizations Hit by AI Security Tool Hijacking — 2026-04-26
- Cursor and Chainguard — Securing the AI Agent Supply Chain — 2026-04-26
- Forcepoint X-Labs — 10 In-the-Wild Indirect Prompt Injection Payloads Targeting AI Agents — 2026-04-26
- SilverFort — Microsoft Entra Agent ID Administrator Scope Overreach — 2026-04-26
- GitGuardian — Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours — 2026-04-26
- 360 Digital Security — AI Agents Find ~1,000 Vulnerabilities, Echoing Claude Mythos — 2026-04-25
- Bishop Fox Releases "Otto Support" MCP Security CTF — 2026-04-25
- LangChain HTMLHeaderTextSplitter SSRF Redirect Bypass (CVE-2026-41481) — 2026-04-25
- CanisterSprawl — Self-Propagating npm Worm Installs LLM Proxy Backdoor — 2026-04-24
- Flowise — CSV Agent Prompt Injection RCE and Cluster of New CVEs (CVE-2026-41264) — 2026-04-24
- Paperclip AI — Unauthenticated RCE via Four-Flaw Authorization Chain (CVE-2026-41679) — 2026-04-24
- TeamPCP — Checkmarx KICS Docker and Bitwarden CLI Compromised in Escalating Supply Chain Campaign — 2026-04-24
- Vercel Breach via Context.ai — Third-Party AI Tool OAuth Cascade — 2026-04-24
- Anthropic Officially Launches Project Glasswing — $100M Commitment, 12 Partners, Thousands of Zero-Days Found — 2026-04-23
- “Comment and Control” — Prompt Injection Hijacks Claude Code, Gemini CLI & Copilot via GitHub — 2026-04-23
- Comment and Control — Prompt Injection Leaks Secrets in Three AI Coding Agents — 2026-04-23
- Forcepoint X-Labs Finds 10 Indirect Prompt Injection Payloads on Live Websites — 2026-04-23
- LiteLLM PyPI Compromised — Multi-Stage Credential Stealer in 3M-Download Package — 2026-04-23
- Lovable — BOLA Exposes AI Chat Histories and Database Credentials in Vibe Coding Platform — 2026-04-23
- npm CanisterWorm — Self-Spreading Supply-Chain Attack Targets AI Agent Tooling — 2026-04-23
- NVIDIA — Indirect AGENTS.md Injection in OpenAI Codex via Malicious Dependencies — 2026-04-23
- Red Hat RHEL AI — Two InstructLab CVEs: Path Traversal & trust_remote_code RCE — 2026-04-23
- Anthropic — Unauthorized Access to Mythos AI Model — 2026-04-22
- Brex — CrabTrap Open-Source LLM-as-a-Judge Proxy for AI Agent Security — 2026-04-22
- CSA Survey — 82% of Enterprises Have Unknown AI Agents in Their Environments — 2026-04-22
- CVE-2026-26144: Excel XSS Chains to Copilot Agent for Silent Data Exfiltration — 2026-04-22
- Mondoo — Free AI Agent Skills Security Checker Launches — 2026-04-22
- Pillar Security — Google Antigravity Sandbox Escape via Prompt Injection — 2026-04-22
- Hacktron — Claude Opus Builds Full Chrome Exploit Chain for $2,283 — 2026-04-21
- Gartner — Agentic AI Will Trigger Security Incidents at Scale — 2026-04-21
- Postiz — CVE-2026-40487 Stored XSS via File Upload Validation Bypass — 2026-04-21
- VulnCheck — Project Glasswing: Only 1 Confirmed CVE Despite Anthropic Mythos Hype — 2026-04-21
- Claude Opus Used to Build Working Chrome Exploit Chain — 2026-04-20
- Suzu Labs — Dark web operators pivot to frontier LLMs for offensive cyber — 2026-04-20
- Vercel Breached via Third-Party AI Tool OAuth Compromise — 2026-04-20
- Georgia Tech Vibe Security Radar — 74 CVEs Traced to AI Coding Tools — 2026-04-20
- CISA Calls for AI Companies to Join CVE Program as CNAs — 2026-04-19
- GreyNoise — 91K attack sessions reveal active targeting of exposed LLM infrastructure — 2026-04-19
- iProov Threat Intelligence Report — 1,151% Surge in iOS Deepfake Injection Attacks — 2026-04-19
- Microsoft — Excel XSS chains to Copilot Agent for clickless data exfiltration (CVE-2026-26144) — 2026-04-19
- OX Security — Full MCP STDIO Command Injection Advisory: CVEs Across LangFlow, LiteLLM, GPT Researcher, Agent Zero — 2026-04-19
- Wiz — AI-Generated Supply Chain Campaign Targets GitHub Actions via pull_request_target — 2026-04-19
- Xcitium ThreatLabs — Malicious LLM routers steal credentials and drain crypto wallets — 2026-04-19
- GreyNoise — 91,403 Attack Sessions Target Exposed LLM Infrastructure — 2026-04-18
- Hadrian — 70 AI Offensive Security Tools Cataloged as Pen Testing Economics Collapse — 2026-04-18
- XCIT Threat Labs — Malicious LLM Routers Inject Payloads and Steal Credentials — 2026-04-18
- Cisco AI Defense — Open-Source Agent Security Toolkit Launch — 2026-04-18
- Gambit Security — Single Hacker Used Claude Code and ChatGPT to Breach Nine Mexican Government Agencies — 2026-04-18
- Abnormal Security — ATHR: AI Voice Agents Automate Full Vishing Attack Chain — 2026-04-17
- Cisco Talos — n8n AI Workflow Platform Abused for Malware Delivery and Device Fingerprinting — 2026-04-17
- Cloudflare — Enterprise MCP Reference Architecture for Secure Agentic Workflows — 2026-04-17
- Google Cloud Threat Intelligence — Defending Enterprises Against AI-Powered Exploitation — 2026-04-17
- Apple Intelligence — Prompt injection bypasses on-device AI guardrails (RSAC 2026) — 2026-04-16
- Flowise — CVSS 10.0 CustomMCP RCE enables full server compromise (CVE-2025-59528) — 2026-04-16
- Microsoft — AI-enabled device code phishing campaign bypasses MFA at scale (April 2026) — 2026-04-16
- Capsule Security — ShareLeak and PipeLeak prompt injection in Copilot Studio and Agentforce — 2026-04-16
- ChatboxAI — MCP StdioClientTransport OS Command Injection (CVE-2026-6130) — 2026-04-13
- OpenAI — Axios Supply Chain Compromise Impacts macOS App Certification — 2026-04-12 18:30
- Anthropic — Command injection vulnerability fixed in Claude Code LSP binary detection — 2026-04-12
- Trend Micro — Sockpuppeting: Single-Line Jailbreak for 11 Major AI Models — 2026-04-12
- Google Chrome — Critical WebML and PrivateAI vulnerabilities expose memory data and enable sandbox escape — 2026-04-11
- Guardian — Claude Mythos AI model demonstrates unprecedented vulnerability discovery capabilities, raising security concerns — 2026-04-11
- ModelContextProtocol — Java SDK DNS rebinding vulnerability allows MCP server takeover (CVE-2026-35568) — 2026-04-09
- Microsoft — CVE-2026-26113/26110 Preview Pane RCE — 2026-04-08
- KuCoin — AI trading agent vulnerabilities cause $45M crypto breaches — 2026-04-05
- Mercor — LiteLLM supply chain breach exposes 4TB of AI training data — 2026-04-05
- Microsoft — Agent Governance Toolkit addresses OWASP AI agent security risks — 2026-04-05
- Microsoft — Azure MCP Server authentication flaw exposes sensitive data (CVE-2026-32211) — 2026-04-03
- Adversa — Claude Code deny rule bypass allows prompt injection of blocked commands — 2026-04-01
- Anthropic — Three OS command injection vulnerabilities in Claude Code CLI and Agent SDK — 2026-04-01
- Anthropic — Claude Code npm source map leak exposes 512K+ lines — 2026-04-01
- arXiv — Agent Skills Security Analysis Framework Vulnerabilities — 2026-04-01
- arXiv — BadSkill: Agent Supply Chain Backdoor Attacks via Model-in-Skill Poisoning — 2026-04-01
- arXiv:2604.11806 — Meerkat Detects Hidden Safety Violations in AI Agent Traces — 2026-04-01
- aws-mcp-server — Command Injection RCE (CVE-2026-5058, ZDI-26-246) — 2026-04-01
- CSA — AI Agent Weaponization Threat Briefing — 2026-04-01
- Tenable Research — Claude Code GitHub Action MCP Server RCE Vulnerability — 2026-04-01
- Comment and Control — Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and Copilot Agent — 2026-04-01
- Depthfirst — $80M Series B for AI Security Platform — 2026-04-01
- Microsoft — GitHub Copilot privacy policy shifts to opt-out AI training model — 2026-04-01
- Google DeepMind — AI Agent Traps Taxonomy Reveals Six Critical Vulnerability Classes — 2026-04-01
- Harness Engineering — LangChain Guardrails Tutorial for Safe AI Agents — 2026-04-01
- Check Point — HexStrike AI MCP Server Command Injection — 2026-04-01
- LangChain-ChatChat — RCE via MCP STDIO Server Configuration (CVE-2026-30617) — 2026-04-01
- Langflow — Critical vulnerability CVE-2026-33309 — 2026-04-01
- Endor Labs — Marimo CVE-2026-39987 Pre-Auth RCE — 2026-04-01
- nginx-ui — MCPwn: Unauthenticated MCP Endpoint Leads to Full Server Takeover (CVE-2026-33032) — 2026-04-01
- Oasis Security — Claude.ai prompt injection & data exfiltration — 2026-04-01
- OpenAI — ChatGPT DNS side channel data exfiltration vulnerability — 2026-04-01
- OpenAI — GPT-5.4-Cyber lowers refusal boundary for defensive cybersecurity — 2026-04-01
- OpenClaw Claude Bridge — Sandbox bypass allows arbitrary tool execution in spawned subprocesses (CVE-2026-39398) — 2026-04-01
- OpenClaw Security Crisis — What 346K Stars & 135K Exposed Instances Teach Us — 2026-04-01
- Praetorian — Indirect Prompt Injection Bypasses LLM Supervisor Agents — 2026-04-01
- PraisonAI — Four critical vulnerabilities expose multi-agent AI systems to sandbox escape, RCE, and data exfiltration — 2026-04-01
- PraisonAI — execute_code() vulnerability allows arbitrary Python code execution in multi-agent systems — 2026-04-01
- Red Hat OpenShift AI — Kubernetes Token Disclosure (CVE-2026-5483) — 2026-04-01
- Token Security — Azure MCP RCE vulnerability enables cloud takeover — 2026-04-01
- ToxSec — AI-Generated Code Leaks Hardcoded Secrets at Scale — 2026-04-01
- Unit 42 — Chrome Gemini Live panel hijack vulnerability enables camera/mic access — 2026-04-01
- Unit 42 — Vertex AI P4SA overprivileged agents expose Google Cloud data — 2026-04-01
- Vitalik Buterin — Warns against AI agent security risks, shares private LLM stack — 2026-04-01
- Wiz Research — Axios npm Supply Chain Compromise Delivers Cross-Platform RAT — 2026-04-01
- WordPress TTS Plugin — CVE-2026-1233 Database Exposure — 2026-04-01
- Zscaler ThreatLabz — Fake Claude Code Source Distributes Vidar & GhostSocks Malware — 2026-04-01
- UK AISI Study — AI Chatbots Ignoring Human Instructions Rising Five-Fold — 2026-03-30
- Cyera Research — LangChain & LangGraph Multiple Vulnerabilities (CVE-2026-34070) — 2026-03-30
- Dev.to — MCP Server Audit Finds 66% Have Critical Vulnerabilities — 2026-03-29
- Offensive Security — MCP server command injection vulnerabilities CVE-2026-5007 and CVE-2026-5023 — 2026-03-29
- Novee — autonomous AI red teaming for LLM applications — 2026-03-29
- Backslash — MCP NeighborJack and over-privileged tool exposure — 2026-03-28
- NIST — Monitoring deployed AI systems in production — 2026-03-28
- TrojAI — Agent runtime intelligence and coding-agent protection — 2026-03-28
- Unit 42 — Boggy Serpens AI-enhanced malware and multi-wave espionage — 2026-03-28
- Check Point — agentic era AI threat landscape — 2026-03-27
- LiteLLM — PyPI supply-chain compromise hits AI gateway — 2026-03-26
- Palo Alto Networks — Prisma AIRS 3.0 adds agent artifact security — 2026-03-26
- Qualys — MCP servers become shadow IT for AI operations — 2026-03-26
- Aqua Security Trivy Supply Chain Attack — 2026-03-23
- Unit 42 — Security tradeoffs of AI agents — 2026-03-22
- Cloudflare — AI Security for Apps GA — 2026-03-19
- JFrog + NVIDIA — Agent Skills Registry adds trust layer for agentic supply chain — 2026-03-19
- Manifold — $8M seed to secure autonomous AI agents at runtime — 2026-03-19
- Microsoft — Detecting prompt abuse in AI tools — 2026-03-19
- JFrog — Universal MCP Registry for AI supply-chain security — 2026-03-18
- Jozu — AI agent disables own security guardrails in 4 commands — 2026-03-18
- Agent Shield — Audit of 17 popular MCP servers finds universal security gaps — 2026-03-14
- Microsoft — AI as Tradecraft: threat actors operationalize AI across the attack lifecycle — 2026-03-14
- Alibaba ROME agent paper documents rogue tool use — 2026-03-12
- alice.io — Caterpillar security auditor — 2026-03-12
- CyberDesserts — ClawHavoc malicious skill campaign — 2026-03-12
- Irregular — Rogue AI agents collaborate to hack systems, exfiltrate data — 2026-03-12
- Google GTIG — AI Threat Tracker: adversarial use update — 2026-03-11
- Google — UNC6426 weaponized LLM tool to steal credentials, escalated to AWS admin in 72h — 2026-03-11
- Balungpisah — Critical prompt injection and rate-limiting flaws found in LLM Gateway — 2026-03-09
- LWN — GitHub issue title prompt injection compromises 4,000 developer machines — 2026-03-09
- HackerNoon — Self-modifying AI malware emerges as major cybersecurity threat — 2026-03-09
- Huntress — Fake OpenClaw installers spread GhostSocks — 2026-03-07
- Noma Security — ContextCrush in Context7 MCP server — 2026-03-07
- AI Agent Security Threat Model 2026 — 2026-03-06
- Check Point Research — Claude Code project-file RCE & key exfil — 2026-03-06
- Securing MCP and Agent Tool Supply Chains — 2026-03-06
- Microsoft Security Blog — malicious AI assistant extensions harvest LLM chat histories — 2026-03-06
- Prompt Injection Defense Playbook (2026) — 2026-03-06
- Cisco Talos — 2025 CVE retrospective (AI-related CVEs double) — 2026-03-06
- VulnerableMCP — MCP security database for real-world tool flaws — 2026-03-06
- Unit 42 — Web-based indirect prompt injection observed in the wild — 2026-03-05
- Techzine — DeepKeep AI Agent Scanner — 2026-03-04
- BlacksmithAI — Multi-agent penetration testing framework — 2026-03-03
- Oasis Security — ClawJacked OpenClaw WebSocket takeover — 2026-03-03
- MIT AI Agent Index — transparency gaps in agent safety reporting — 2026-03-01
- Orca Security — RoguePilot GitHub Copilot prompt injection — 2026-03-01
- SD Times — MCP privacy and security gaps — 2026-02-28
- IBM — X-Force Threat Intelligence Index 2026 — 2026-02-27
- Provos.org — IronCurtain agent sandbox architecture — 2026-02-27
- Check Point Research — Claude Code hooks/MCP RCE — 2026-02-26
- CrowdStrike — 2026 Global Threat Report: AI-accelerated adversaries — 2026-02-26
- Trail of Bits — Comet prompt-injection audit — 2026-02-26
- Pillar Security — Operation Bizarre Bazaar LLMjacking campaign — 2026-02-25
- Socket — SANDWORM_MODE npm worm targets AI coding tools — 2026-02-25
- Veza — Access Agents for AI identity governance — 2026-02-25
- GitHub Advisory — Cline unauthorized npm publish added postinstall — 2026-02-24
- Kai Security AI — Honeypot MCP server logs AI agent probing — 2026-02-23
- Phoenix Security — SANDWORM_MODE npm worm poisons AI toolchains — 2026-02-23
- Unit 42 — 2026 IR report on AI-accelerated attacks — 2026-02-23
- Cisco — State of AI Security 2026 report — 2026-02-22
- Microsoft — Copilot summarized confidential emails despite DLP labels — 2026-02-21
- Microsoft Security Blog — Running OpenClaw safely — 2026-02-21
- NIST — AI Agent Standards Initiative — 2026-02-21
- OpenAI — ChatGPT Lockdown Mode — 2026-02-21
- Check Point — AI assistants as C2 proxies — 2026-02-20
- mbgsec — Cline issue-triage prompt injection led to npm supply-chain publication — 2026-02-20
- Google GTIG — AI Threat Tracker: distillation & integration — 2026-02-20
- Praetorian — MCP server attack surface research — 2026-02-20
- Cerbos — MCP Authorization for AI Agents — 2026-02-19
- PromptArmor — Link preview data exfiltration in agent chats — 2026-02-19
- Snyk — AI Agent Guardrails — 2026-02-19
- Straiker STAR Labs — SmartLoader poisons an Oura MCP server — 2026-02-19
- University of Toronto — MCP security risk guidance — 2026-02-19
- Microsoft Security Blog — Copilot Studio agent misconfigurations — 2026-02-18
- OWASP — Secure MCP Server Development Guide — 2026-02-18
- Cyata — Anthropic MCP Git server prompt-injection CVEs — 2026-02-17
- LayerX — Claude Desktop Extensions zero-click RCE via calendar event — 2026-02-17
- AgentAudit — MCP server security findings across 194 packages — 2026-02-16
- Microsoft Security Blog — AI recommendation poisoning — 2026-02-13
- Praetorian — Augustus open-source LLM prompt-injection scanner — 2026-02-11
- Ars Technica — Moltbook prompt worms and viral prompt injection — 2026-02-10
- Endor Labs — MCP needs AppSec as classic vulns hit agent tooling — 2026-02-10
- Levo — Launch Week 2026 adds AI firewall + MCP security testing — 2026-02-10
- Trend Micro — OpenClaw’s Agentic Assistant Risk Map — 2026-02-10
- Operant AI — Agent Protector for runtime agent security — 2026-02-09
- Radware — Agentic AI Protection Solution launch — 2026-02-09
- AuthMind — OpenClaw’s 230 malicious skills expose agentic supply-chain risk — 2026-02-07
- Infosecurity Magazine — ZombieAgent zero-click prompt injection in ChatGPT connectors — 2026-02-07
- Darktrace — 2026 State of AI Cybersecurity Report: 76% of Security Pros Worried About AI Agent Risk — 2026-02-06
- Noma Security — DockerDash: Prompt Injection in Docker Ask Gordon AI Enables RCE via Image Metadata — 2026-02-06
- ThreatDown — 2026 State of Malware: AI Drives Machine-Scale Cyberattacks — 2026-02-05
- Vectra AI — From Clawdbot to OpenClaw: Automation as a Backdoor — 2026-02-04
- NVIDIA AI Red Team — Mandatory sandbox controls for agentic coding workflows — 2026-02-03
- Clutch Security — 95% of enterprise MCP servers run on endpoints with zero security visibility — 2026-02-02
- GitGuardian / NHIcon 2026 — Agentic AI forces a paradigm shift in non-human identity security — 2026-02-02
- InstaTunnel — Agent hijacking and intent breaking: the goal-oriented attack surface — 2026-02-02
- Keyfactor — Two-thirds of enterprises say AI agents are a bigger security risk than humans — 2026-02-02
- Christian Schneider — From LLM to agentic AI: how agents amplify prompt injection into kill chains — 2026-02-02
- Check Point / Lakera — 40% of 10,000 MCP servers found to have security weaknesses — 2026-02-01
- Dev.to — Implementing Sudo for AI Agents — 2026-02-01
- The Register — Ungoverned AI agent identities are the new shadow IT — 2026-02-01
- Reuters — Open-Source AI Models Vulnerable to Criminal Misuse — 2026-02-01
- Trend Micro — ÆSIR: AI Agents Finding Zero-Days in AI Infrastructure — 2026-02-01
- arXiv — EchoLeak: zero-click prompt injection in Microsoft 365 Copilot — 2026-01-31
- Cisco — Personal AI agents like OpenClaw are a security nightmare — 2026-01-31
- CrowdStrike — Agentic tool chain attacks (tool poisoning, shadowing, rugpull) — 2026-01-31
- DataDome — MCP prompt injection & tool poisoning defenses — 2026-01-31
- LangChain — January 2026 newsletter (agent robustness + observability/evals) — 2026-01-31
- GitHub Advisory — node-tar hardlink path traversal (CVE-2026-24842) — 2026-01-31
- Pen Test Partners — Eurostar chatbot guardrail bypass + ID tampering — 2026-01-31
- Snyk — Clawdbot/Moltbot prompt injection: ‘one email away from disaster’ — 2026-01-31
- Wiz — ZeroDay.cloud: cloud + AI infra zero-days — 2026-01-31
- AWS/Wiz — CodeBreach: unanchored ACTOR_ID filters in CodeBuild webhooks — 2026-01-30
- Bitdefender — Hugging Face abused to distribute polymorphic Android RAT payloads — 2026-01-30
- Bizarre Bazaar: attackers monetizing exposed LLM & MCP endpoints (LLMjacking) — 2026-01-30
- Operation ‘Bizarre Bazaar’: LLMjacking campaign targets exposed LLM/MCP endpoints (Pillar Security) — 2026-01-30
- CISA/NCSC-UK/FBI — Secure connectivity principles for OT networks — 2026-01-30
- Cisco Security Blog — Foundation AI’s push for agentic security systems — 2026-01-30
- curl — Ending its bug bounty after an AI slop flood — 2026-01-30
- Google Developers Blog — Gemini CLI hooks for policy & automation — 2026-01-30
- Google: Gemini 3 in Chrome adds an agentic ‘auto browse’ workflow — 2026-01-30
- GreyNoise — Threat actors actively targeting exposed LLM endpoints — 2026-01-30
- Bitdefender — Android dropper used Hugging Face datasets to deliver RAT payloads — 2026-01-30
- Kaspersky — OWASP Agentic Top 10 (2026): practical risks + controls for AI agents — 2026-01-30
- Model Context Protocol — MCP Apps: UI components inside agent chats — 2026-01-30
- Microsoft: runtime inspection to block risky AI agent tool calls — 2026-01-30
- Microsoft — turning threat reports into detection insights with AI — 2026-01-30
- n8n: sandbox escape bugs lead to full RCE in self-hosted instances — 2026-01-30
- NIST/CAISI — RFI on security practices for AI agents — 2026-01-30
- OpenAI — Hardening ChatGPT Atlas against prompt injection — 2026-01-30
- Varonis — Reprompt: single-click Copilot prompt injection chain for silent data exfiltration — 2026-01-30
- Varonis — Reprompt one-click Copilot session hijack (patched) — 2026-01-30
- AI Email Triage Workflow (labels, summaries, suggested replies) — 2026-01-29
- AI security news digest: what to watch this week — 2026-01-29
- CISA/NSA/FBI — Deploying AI systems securely (joint guidance) — 2025-06-03
- Google — SAIF (Secure AI Framework): a practitioner’s map — 2025-05-12
- OWASP — Top 10 for LLM Apps: what to fix first — 2025-04-18
- NIST — AI Risk Management Framework (RMF) for security teams — 2025-03-10