High-signal AI/security/automation notes.
Security Boulevard analysis finds the MCP ecosystem has 973 packages with 71% single-maintainer, 45% failure rate across 150+ LLMs for AI-generated code, and 55.8% provable vulnerability rate in formal verification.
SpecterOps demonstrates how SQL Server 2025 native AI features — sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, AI_GENERATE_EMBEDDINGS — can be abused for stealthy data exfiltration and covert C2 channels.
CVE-2026-41523 and CVE-2026-54235 reveal how assert-based security checks and float validation gaps in vLLM enable RCE and GPU kernel manipulation.
Tenet Security demonstrates Agentjacking: injected Sentry error events hijack AI coding agents via MCP, achieving 85% execution rate across Claude Code, Cursor, and Codex.
CISA adds actively exploited LiteLLM command injection to KEV catalog; chained with Starlette CVE-2026-48710, it yields unauthenticated RCE on AI gateway hosts.
Socket researchers discovered 23 new malicious PyPI artifacts from the Shai-Hulud campaign, featuring split-staging loaders, native extension payloads, and LLM anti-analysis tricks targeting MCP developers.
A new arXiv paper presents FORGE, a multi-agent system that bridges exploit generation, vulnerability prioritization, and detection engineering across 603 CVEs.
Brave researchers demonstrated indirect prompt injection attacks against both a cloud-hosted AI browsing API and a local macOS assistant, proving neither deployment model is immune.
AWS AgentCore CLI (CVSS 9) lets an authenticated account member inject arbitrary Python into generated agent source files via triple-quote escaping bypass.
A critical RCE flaw in Hugging Face Transformers lets attackers execute code via a poisoned config.json field, bypassing trust_remote_code=False.
Microsoft expanded its AI agent failure taxonomy with seven new critical attack vectors, including MCP/plugin abuse, session context contamination, and gradual reasoning bias injection.
OWASP released a risk-quadrant maturity framework for agentic AI, mapping autonomy against governance to flag high-risk deployments as red cells.
Varonis Threat Labs tricked an OpenClaw email agent into forwarding AWS IAM keys, database passwords, and CRM exports to an attacker after receiving a convincing phishing email.
Anthropic splits its Mythos-class model into two tiers: unrestricted Mythos 5 for vetted cyber professionals and safeguarded Fable 5 that falls back to Opus 4.8 for cybersecurity queries.
Poise achieves 89.3% attack success rate on LLM agent skills by exploiting position-aware injection — and bypasses current scanner defenses through false-positive blending.
CISA added CVE-2026-42271 (LiteLLM command injection) to its Known Exploited Vulnerabilities catalog on June 8, 2026 — confirming active exploitation of the chained BadHost RCE chain against AI serving infrastructure.
University of Toronto researchers built an AI-powered worm using free local LLMs that self-replicated across 27 of 33 systems in a simulated enterprise network over five generations.