Posts
High-signal AI/security/automation notes.
OWASP — Agent Memory Guard, a Runtime Defense Against Memory Poisoning
OWASP releases Agent Memory Guard, a drop-in middleware framework that wraps LangChain, LlamaIndex, and CrewAI memory APIs to defend against the ASI06 memory poisoning threat class.
Pentest Swarm — AI Autonomous Penetration Testing Tool with MCP Server
Pentest Swarm AI integrates nmap, sqlmap, Burp, and Metasploit into an autonomous pentesting tool exposed as an MCP server.
PraisonAI CVE-2026-47408 — Unauthenticated A2A eval() RCE
PraisonAI CVE-2026-47409/47414 — Workspace Takeover and Cross-Workspace IDOR
Two new PraisonAI CVEs enable workspace takeover via missing member-removal authorization and cross-workspace label manipulation through unvalidated IDOR parameters.
vLLM CVE-2026-22778/34756 — Heap Leak and DoS in Multimodal Serving
Two vLLM CVEs: a multimodal heap-address leak weakening ASLR (CVE-2026-22778) and an unbounded n-parameter DoS in the OpenAI-compatible API (CVE-2026-34756).
arXiv — IterInject: Feedback-Guided Iterative Prompt Injection Against Agents
Shanghai Jiao Tong University researchers introduce IterInject, an indirect prompt injection framework that uses LLM-driven iterative optimization to adapt payloads against agent defenses, achieving full success on 5 of 9 Claude Code targets.
CERT-In — 12-hour patch mandate calibrated to AI exploitation speed
Permiso — ChatGPhish Turns ChatGPT Summaries Into a Phishing Surface
Detectify — MCP Server brings deterministic vuln scanning into AI coding agents
Detectify launches an MCP Server that exposes its scanning engines to AI coding agents, enabling autonomous vulnerability finding, patching, and validation in real time.
Obsidian — Flowise CVE-2026-40933 MCP stdio Supply-Chain RCE
Obsidian Security releases PoC exploit for CVE-2026-40933 (CVSS 9.9), a systemic MCP stdio command injection in Flowise that enables one-click RCE via crafted chatflow import.
Geordie — $30M Series A for AI Agent Security and Governance
Geordie raises $30M Series A led by Balderton Capital to build a purpose-built security and governance platform for AI agents at enterprise scale.
WithSecure — GreyVibe Russia-Linked Group Supercharges Ops with AI
WithSecure documents GreyVibe, a Russia-nexus threat group using ChatGPT, Gemini, and Ideogram AI across every attack phase — from lure creation to malware development.
Push Security — LLMShare Campaign Abuses ChatGPT Sharing to Deliver Malware
arXiv — AgentSecBench: Formal Security Framework for LLM Agents
AgentSecBench introduces a formal three-game framework measuring instruction integrity, retrieval confidentiality, and capability integrity in LLM agent systems.
MemMorph — Tool Hijacking in LLM Agents via Memory Poisoning
arXiv: Real-World Prompt Injection Attacks in LLM-Based Resume Screening
New arXiv paper measures prompt injection attacks in production LLM resume screening systems, testing prevention, detection, and localization defenses across real-world HR workflows.
Flashpoint — Deepfake KYC Bypass Kits Sold as SaaS to Criminals
Flashpoint tracked 63,763 April posts advertising AI-powered KYC bypass toolkits, complete with live video spoofing, voice cloning, and platform-specific updates.
JFrog — 2026 Supply Chain Report: npm Attacks Up 451%, 495 Malicious AI Models
jqwik Maintainer Sneaks Data-Nuking Prompt Injection Into AI Coding Agents
A frustrated maintainer of the jqwik Java property-based testing library embedded a hidden prompt injection in test output, instructing AI coding agents to delete all project code and tests.