Posts
High-signal AI/security/automation notes.
OpenClaw AI Agent — WhatsApp Message to Host RCE via Sandbox Bypass
Three high-severity vulnerabilities in OpenClaw let attackers chain environment variable injection, git transport abuse, and Docker sandbox escape to achieve host-level code execution via WhatsApp messages.
HalluSquatting — Agentic Botnets via LLM Hallucinated Resource Names
Tel Aviv University researchers demonstrate how attackers can weaponize LLM hallucinations to establish agentic botnets, achieving 100% attack success against multiple AI coding assistants.
CrowdStrike Prompt Injection Taxonomy — 200+ Techniques Cataloged
CrowdStrike expands its prompt injection taxonomy to over 200 techniques, revealing how attacks against AI agents are fragmenting into composite chains.
Unit 42 — Pickle in the Middle: Cross-Tenant RCE in Google Vertex AI
Palo Alto Networks Unit 42 disclosed a critical vulnerability in Google Cloud Vertex AI SDK that allowed cross-tenant model poisoning and remote code execution via bucket squatting.
CISA — Langflow Becomes First AI Agent Platform in KEV Catalog (CVE-2026-55255)
CISA adds Langflow CVE-2026-55255 to its Known Exploited Vulnerabilities catalog — the first AI agent orchestration platform ever listed — with a July 10 deadline.
arXiv — GitHub Copilot Refuses Harmful Requests in Chat, Writes Them in Code
New research demonstrates workflow-level jailbreak construction: coding agents that refuse harmful prompts in chat will produce the same harmful content when asked to write it as code.
ESET — 3,000+ Malicious AI Skills Found in Agent Ecosystem Scan
European Commission — EU Action Plan on Cybersecurity and AI
The EU published an Action Plan on July 7, 2026 to address risks and opportunities of advanced AI for cybersecurity, including AI model evaluation, structured access, and secure testing platforms.
Fiddler AI — AI Coding Agent Threat Models and Controls
Fiddler AI maps the full coding-agent attack surface — prompt injection, supply-chain poisoning, credential leaks, MCP spoofing — and proposes runtime guardrails.
When Your Software Supply Chain Includes AI Writing Your Code
Sygnia — Lone Attacker Uses Agentic AI to Compromise AWS in 72 Hours
Sygnia reports a single threat actor used agentic AI workflows to execute a full cloud compromise in 72 hours — a campaign that would have taken weeks manually.
TeamPCP — Supply Chain Compromise of Trivy, LiteLLM, and KICS Feeds VECT Ransomware Credential Archive
TeamPCP poisoned Trivy, Checkmarx KICS, LiteLLM, and Telnyx SDK to harvest 500K+ CI/CD credentials — VECT ransomware then selected victims from the archive.
arXiv — Agent Data Injection (ADI): New IPI Category Bypasses All Defenses
Seoul National University and UIUC researchers introduce Agent Data Injection, a new class of indirect prompt injection that exploits lack of trusted/untrusted data isolation in LLM agents.
CVE-2026-59707 — LocalAI Unauthenticated SSRF in Model Apply Endpoint
LocalAI before the latest patch contains an unauthenticated SSRF vulnerability in POST /models/apply that allows attackers to fetch arbitrary internal URLs.
GitLost — GitHub Agentic Workflows Leak Private Repos via Prompt Injection
Noma Labs discovered GitLost, a critical indirect prompt injection in GitHub Agentic Workflows that lets unauthenticated attackers exfiltrate private repository content.
Langroid CVE-2026-55615 — Prompt-to-Cypher Injection Enables RCE via Neo4j
vLLM Patches Two New DoS CVEs in v0.24.0 — Audio Memory Exhaustion and Regex ReDoS
CVE-2026-55646 lets unauthenticated API callers exhaust memory via oversized audio uploads; CVE-2026-55574 enables indefinite inference worker hangs via adversarial regex patterns.
vLLM CVE-2026-55646 — Audio Upload Memory Exhaustion DoS (CVSS 6.5)
vLLM speech-to-text endpoints allocate full upload before enforcing audio file-size limit, enabling remote memory exhaustion DoS. Fixed in 0.24.0.
Zscaler — Indirect Prompt Injection Tricks AI Agents Into Crypto Payments
Two campaigns use SEO poisoning and indirect prompt injection to manipulate AI agents into making cryptocurrency payments or trusting fraudulent DeFi platforms.