NVIDIA — SkillSpector Open-Source Scanner for AI Agent Skills
NVIDIA released SkillSpector, an open-source security scanner that detects 64 vulnerability patterns across 16 categories in AI agent skills before installation.
High-signal AI/security/automation notes.
NVIDIA released SkillSpector, an open-source security scanner that detects 64 vulnerability patterns across 16 categories in AI agent skills before installation.
A critical OS command injection vulnerability (CVSS 9.8) in radare2-mcp allows unauthenticated remote attackers to execute arbitrary commands via the JSON-RPC interface.
A new Hades-family wave of the Shai-Hulud supply chain campaign compromises 23 PyPI packages with MCP-themed typosquats and a novel LLM anti-analysis technique.
A June 2026 US executive order directs an AI cybersecurity clearinghouse, CISA guidance for AI-enabled defenses, and federal system upgrades within 30 days.
Anthropic expands Project Glasswing to ~200 organizations across 15+ countries; Claude Mythos Preview has surfaced over 10,000 high- and critical-severity vulnerabilities in widely used software, with first public CVE wave expected July 2026.
Opening an attacker-supplied .NET solution in the Roslyn CodeLens MCP server loads and executes arbitrary code, turning code-intelligence tooling into a remote-code-execution vector.
A flag-injection flaw in mcp-server-kubernetes lets attacker-controlled logs exfiltrate operator K8s bearer tokens via indirect prompt injection.
Horizon3 demonstrates a full unauthenticated RCE chain against LiteLLM by combining CVE-2026-42271 with the Starlette BadHost auth bypass.
OWASP unveiled an Enterprise Adoption Maturity Model mapping agentic AI deployment levels against governance readiness at Infosecurity Europe 2026.
OWASP Incubator Project CVE Lite CLI adds AI assistant integration, writing skill files for Claude Code, Codex CLI, Gemini CLI, and Copilot so agents can analyze scan output and generate prioritized fix plans.
Analysis of 3,500+ CVE-exploit pairs shows mean time-to-weaponization dropped from 53 days in 2024 to roughly 24 hours in 2026, driven by AI-powered exploit development.
Sysdig TRT observes the first agentic threat actor to perform Docker container escape, host breakout via nsenter, and Kubernetes Secret store exfiltration.
Kodem Security and Intezer research maps five methods threat actors use to access LLM inference for free, from underground offensive models to exposed self-hosted servers.
A self-replicating npm worm named Miasma compromised 57 packages across 286 malicious versions, using binding.gyp to execute at install time and steal multi-cloud credentials.
The NSA released a Cybersecurity Information Sheet warning that MCP adoption has outpaced its security model, citing weak access controls, open-ended serialization, and unsafe tool execution.
A poisoned Nx Console VS Code extension (CVE-2026-48027) exfiltrated developer credentials and led to the theft of 3,800 internal GitHub repositories by TeamPCP.
OpenAI launched Lockdown Mode for ChatGPT on June 6, 2026 — an optional toggle that disables outbound-connected features to break the data-exfiltration leg of prompt-injection attacks.
Sophos observed a threat actor using Cursor and Claude Opus agents to develop and test an EDR-evasion framework tied to ransomware deployment and data theft operations.
Trail of Bits demonstrates multiple bypass techniques against AI skill scanners from ClawHub, Cisco, and Vercel, showing that automated scanning alone cannot secure agent skill ecosystems.