Posts
High-signal AI/security/automation notes.
arXiv: Real-World Prompt Injection Attacks in LLM-Based Resume Screening
New arXiv paper measures prompt injection attacks in production LLM resume screening systems, testing prevention, detection, and localization defenses across real-world HR workflows.
Flashpoint — Deepfake KYC Bypass Kits Sold as SaaS to Criminals
Flashpoint tracked 63,763 April posts advertising AI-powered KYC bypass toolkits, complete with live video spoofing, voice cloning, and platform-specific updates.
JFrog — 2026 Supply Chain Report: npm Attacks Up 451%, 495 Malicious AI Models
jqwik Maintainer Sneaks Data-Nuking Prompt Injection Into AI Coding Agents
A frustrated maintainer of the jqwik Java property-based testing library embedded a hidden prompt injection in test output, instructing AI coding agents to delete all project code and tests.
Langroid CVE-2026-25879 — Prompt-to-SQL Injection Leads to RCE
Sysdig: First LLM Agent-Driven Intrusion via Marimo CVE-2026-39987
Sysdig documents the first observed intrusion where an LLM agent composed post-exploitation in real time — from Marimo RCE to full PostgreSQL database dump in under one hour.
UVCyber MCP Threat Advisory: 40+ CVEs, Tool Poisoning, and the Missing Auth Layer
UVCyber publishes a comprehensive MCP threat advisory covering 40+ CVEs, tool poisoning, rug pulls, and the architectural gap of missing built-in authentication in the Model Context Protocol.
vLLM CVE-2026-4944 — Hardcoded trust_remote_code Bypass Enables RCE
vLLM 0.14.1 hardcodes trust_remote_code=True in two model files, bypassing user security settings and enabling remote code execution via malicious HuggingFace models.
Cogent — AI exploit dev shrinks weaponization from 125 days to 12 hours
Cogent reports AI-assisted exploit development has collapsed vulnerability-to-weaponization timelines from 125 days to 12 hours, outpacing scanner-based detection cycles.
Axis Intelligence — AI Model Vulnerability Tracker: 71% Attack Success Rate Across Six Frontier Models
Axis Intelligence tested 312 LLM attack vectors against six production models — 71% succeeded against at least one, 23% against all six, and system-prompt extraction works in 31% of deployments.
Check Point — AI Attacks Go Mainstream: Single Operator Breached 9 Mexican Agencies Using AI Orchestration
GlassWorm — developer-targeting botnet takedown (CrowdStrike, Google)
CrowdStrike, Google and Shadowserver simultaneously disrupt all four C2 channels of the GlassWorm malware campaign that has poisoned 300+ GitHub repos since 2025.
TechRepublic / TechTimes — The AI Agent Governance Gap: 88% of Deployments Already Breached
Two 2026 reports reveal that 88% of AI agent operators have already experienced security incidents, 63% cannot enforce purpose limits on agents, and 60% cannot terminate misbehaving agents.
Megalodon — Mass GitHub CI/CD Supply Chain Attack Hits 5,561 Repos
Perplexity Bumblebee — Open-Source Scanner for Dev Endpoints and MCP Configs
Perplexity open-sources Bumblebee, a read-only Go scanner that inventories developer machines for compromised npm, PyPI, Go modules and MCP configurations.
Starlette CVE-2026-48710 "BadHost" — FastAPI AI Infrastructure Exposed
A single-character Host header flaw in Starlette bypasses authentication in thousands of FastAPI-based AI tools, model proxies, and MCP servers.
Adversa AI — SymJack symlink-to-RCE via AI coding agents
SymJack turns AI coding agents into supply-chain delivery systems: disguised symlinks inject malicious MCP servers that run unsandboxed on developer restart.
Trend Micro "Return-to-Tool" — AI Agents as Attack Chains
Anthropic Claude Code Security-Guidance Plugin — Three-Layer In-Session Vulnerability Detection
Anthropic releases a free security-guidance plugin for Claude Code that runs deterministic pattern matching, a separate-model review, and agentic commit-time checks.