Posts
High-signal AI/security/automation notes.
Check Point — IKEv1 VPN Auth Bypass (CVE-2026-50751) Exploited by Qilin Ransomware
Check Point discloses CVE-2026-50751, a critical IKEv1 authentication bypass actively exploited since May by Qilin ransomware; CISA adds it to the KEV catalog.
Claude Code MCP Token Theft — npm Package MITM
Cymulate — InversePrompt Bypasses Claude Code Path Restrictions & Command Injection (CVE-2025-54794, CVE-2025-54795)
Docker — AI Coding Agent Horror Stories: Filesystem Destruction Risk
Docker publishes real-world case studies of AI agents destroying user data outside sandboxed workspaces, including a Claude Cowork incident that deleted 15,000+ photos.
Google Sites — Fake Claude Code and Codex Installer Phishing Campaign
Threat actors use Google Sites-hosted fake Claude Code and OpenAI Codex installer pages to trick developers into running credential-stealing commands.
depthfirst AI Agent Finds 21 FFmpeg Zero-Days
An autonomous AI agent found 21 previously unknown vulnerabilities in FFmpeg, including bugs latent for up to 23 years, at a cost of roughly $1,000 per scan run.
LiteLLM PyPI Supply-Chain Attack — Malicious Versions 1.82.7 & 1.82.8 Published Directly to PyPI
NVIDIA — SkillSpector Open-Source Scanner for AI Agent Skills
NVIDIA released SkillSpector, an open-source security scanner that detects 64 vulnerability patterns across 16 categories in AI agent skills before installation.
CVE-2026-6942 — radare2-mcp Command Injection
A critical OS command injection vulnerability (CVSS 9.8) in radare2-mcp allows unauthenticated remote attackers to execute arbitrary commands via the JSON-RPC interface.
Shai-Hulud — Hades Branch Poisons 23 PyPI Packages Targeting MCP Developers
A new Hades-family wave of the Shai-Hulud supply chain campaign compromises 23 PyPI packages with MCP-themed typosquats and a novel LLM anti-analysis technique.
White House AI Executive Order — Cybersecurity Clearinghouse & AI Defenses
A June 2026 US executive order directs an AI cybersecurity clearinghouse, CISA guidance for AI-enabled defenses, and federal system upgrades within 30 days.
Anthropic — Project Glasswing Expands Mythos Preview to 200 Organizations, 10,000+ Vulnerabilities Found
Anthropic expands Project Glasswing to ~200 organizations across 15+ countries; Claude Mythos Preview has surfaced over 10,000 high- and critical-severity vulnerabilities in widely used software, with first public CVE wave expected July 2026.
CVE-2026-45555 — Roslyn CodeLens MCP Server RCE
Opening an attacker-supplied .NET solution in the Roslyn CodeLens MCP server loads and executes arbitrary code, turning code-intelligence tooling into a remote-code-execution vector.
CVE-2026-47250 — MCP Server Kubernetes Bearer Token Exfiltration
A flag-injection flaw in mcp-server-kubernetes lets attacker-controlled logs exfiltrate operator K8s bearer tokens via indirect prompt injection.
Horizon3 — CVE-2026-42271 Chained with BadHost for Unauthenticated LiteLLM RCE
Horizon3 demonstrates a full unauthenticated RCE chain against LiteLLM by combining CVE-2026-42271 with the Starlette BadHost auth bypass.
OWASP — Agentic AI Security Maturity Framework at Infosecurity Europe 2026
OWASP unveiled an Enterprise Adoption Maturity Model mapping agentic AI deployment levels against governance readiness at Infosecurity Europe 2026.
OWASP — CVE Lite CLI Brings AI Agent Integration to Local-First Vulnerability Scanning
OWASP Incubator Project CVE Lite CLI adds AI assistant integration, writing skill files for Claude Code, Codex CLI, Gemini CLI, and Copilot so agents can analyze scan output and generate prioritized fix plans.
Picus Security — CVE Weaponization Time Collapses to 24 Hours in 2026
Analysis of 3,500+ CVE-exploit pairs shows mean time-to-weaponization dropped from 53 days in 2024 to roughly 24 hours in 2026, driven by AI-powered exploit development.
Sysdig — Agentic Threat Actor Performs Container Escape and Kubernetes Credential Replay
Sysdig TRT observes the first agentic threat actor to perform Docker container escape, host breakout via nsenter, and Kubernetes Secret store exfiltration.