Microsoft — CVE-2026-35435 Azure AI Foundry Agent Privilege Escalation
Microsoft patched a CVSS 8.6 flaw in Azure AI Foundry and M365 Published Agents that allowed forged authorization tokens to bypass access controls.
High-signal AI/security/automation notes.
Microsoft patched a CVSS 8.6 flaw in Azure AI Foundry and M365 Published Agents that allowed forged authorization tokens to bypass access controls.
Push Security uncovers LLMShare: a live malvertising campaign abusing ChatGPT and Claude share links to host fake outage pages and deliver malware from trusted AI domains.
A functional npm package with 29,000+ weekly downloads secretly exfiltrated Codex auth tokens and was distributed through malicious Android apps on Google Play.
Salt Security survey: 90% of security leaders have concerns about AI-generated code, yet 38% still rely on manual review — governance has not kept pace.
New arXiv paper introduces managed autonomy theory: a four-layer framework that formally mandates agent escalation, constrains invalid outputs, and ensures governance reachability when agent reliability diminishes.
New research shows harmless-looking prompts can covertly increase package hallucination rates in coding agents, creating software supply chain risks that evade existing defenses.
A DEF CON Singapore talk demonstrated how chained indirect prompt injection, HTML preview exfiltration, delayed tool invocation, and memory poisoning created a persistent backdoor in M365 Copilot (CVE-2026-24299).
Google DeepMind scans billions of web pages and finds a 32% quarterly rise in indirect prompt injections, with payloads containing payment instructions aimed at AI agents with financial access.
CVSS 9.4 flaw in Google MCP Toolbox for Databases lets unauthenticated attackers abuse DNS rebinding via a hardcoded wildcard CORS header on the SSE transport.
Mercor confirmed a cascading supply-chain attack through compromised LiteLLM packages, resulting in 4 TB of internal data exfiltration including Slack archives, source code, and contractor PII.
Microsoft identifies 14 malicious npm packages from actor vpmdhaj harvesting AWS, Vault, and GitHub Actions secrets from AI and developer environments.
OpenAI requires hardware-backed passkeys for Trusted Access for Cyber program users starting June 1, 2026, setting an identity-security precedent for AI operator access.
STAR Labs developed four complete exploit chains targeting LiteLLM across versions 1.82.3 to 1.83.14, escalating from internal user keys to server RCE.
Multiple CVEs across vLLM, MCP reference servers, and agent tooling expose AI inference and orchestration layers to RCE, DoS, and path traversal.
CISA adds CVE-2026-0257 to its KEV catalog after Rapid7 confirms active exploitation of the PAN-OS GlobalProtect authentication bypass.
The FBI warns of Kali365, a PhaaS platform using AI-generated lures and voice cloning to steal Microsoft 365 OAuth tokens via device-code phishing.
OWASP classified ASI06 memory poisoning in early 2026 — malicious instructions written to long-term agent memory that fire weeks later with the credibility of memory itself.