Horizon3 — CVE-2026-42271 Chained with BadHost for Unauthenticated LiteLLM RCE
Horizon3 demonstrates a full unauthenticated RCE chain against LiteLLM by combining CVE-2026-42271 with the Starlette BadHost auth bypass.
High-signal AI/security/automation notes.
Horizon3 demonstrates a full unauthenticated RCE chain against LiteLLM by combining CVE-2026-42271 with the Starlette BadHost auth bypass.
OWASP unveiled an Enterprise Adoption Maturity Model mapping agentic AI deployment levels against governance readiness at Infosecurity Europe 2026.
OWASP Incubator Project CVE Lite CLI adds AI assistant integration, writing skill files for Claude Code, Codex CLI, Gemini CLI, and Copilot so agents can analyze scan output and generate prioritized fix plans.
Analysis of 3,500+ CVE-exploit pairs shows mean time-to-weaponization dropped from 53 days in 2024 to roughly 24 hours in 2026, driven by AI-powered exploit development.
Sysdig TRT observes the first agentic threat actor to perform Docker container escape, host breakout via nsenter, and Kubernetes Secret store exfiltration.
Kodem Security and Intezer research maps five methods threat actors use to access LLM inference for free, from underground offensive models to exposed self-hosted servers.
A self-replicating npm worm named Miasma compromised 57 packages across 286 malicious versions, using binding.gyp to execute at install time and steal multi-cloud credentials.
The NSA released a Cybersecurity Information Sheet warning that MCP adoption has outpaced its security model, citing weak access controls, open-ended serialization, and unsafe tool execution.
A poisoned Nx Console VS Code extension (CVE-2026-48027) exfiltrated developer credentials and led to the theft of 3,800 internal GitHub repositories by TeamPCP.
OpenAI launched Lockdown Mode for ChatGPT on June 6, 2026 — an optional toggle that disables outbound-connected features to break the data-exfiltration leg of prompt-injection attacks.
Sophos observed a threat actor using Cursor and Claude Opus agents to develop and test an EDR-evasion framework tied to ransomware deployment and data theft operations.
Trail of Bits demonstrates multiple bypass techniques against AI skill scanners from ClawHub, Cisco, and Vercel, showing that automated scanning alone cannot secure agent skill ecosystems.
A cluster of recent disclosures reveals widespread RCE vulnerabilities across AI coding agents: SymJack affects six tools via symlink hijacking, TrustFall enables one-click RCE through regressed trust dialogs, and Copirate 365 demonstrates persistent Copilot backdoors at DEF CON.
JFrog discovers IronWorm, a Rust-built self-replicating npm worm with eBPF kernel rootkit that harvests AI developer credentials (Codex, Anthropic, Gemini, Cursor) and propagates via GitHub.
Kiteworks research identifies a lethal trifecta — any AI agent that accesses private data, processes untrusted content, and can communicate externally is structurally exploitable, confirmed by documented production failures.
A parallel arm of the Miasma worm campaign pushes malicious commits to 120+ GitHub repos, exploiting Claude Code, Cursor, and VS Code auto-run features to detonate a credential harvester on folder open.