High-signal AI/security/automation notes.
Microsoft open-sources an AI Agent Governance Toolkit covering all 10 OWASP Agentic Top 10 risks, with policy enforcement, zero-trust identity, and execution sandboxing for autonomous agents.
Two critical Microsoft Semantic Kernel flaws (CVSS 9.8) escalate indirect prompt injection into remote code execution on agent hosts via eval() and unsafe file download.
An ACM paper testing 10 open-source models across 167 attack scenarios finds multi-turn reasoning jailbreaks remain unsolved even with lightweight defenses applied.
Three prompt injection variants that bypass traditional WAF and EDR detection: indirect RAG injection, second-order tool-call injection, and conversation-history poisoning.
TrapDoor campaign weaponizes .cursorrules and CLAUDE.md files via cross-ecosystem supply chain attacks on npm, PyPI, and Crates.io to hijack AI coding assistants.
1Password partners with OpenAI to deliver an Environments MCP Server for Codex, issuing just-in-time scoped credentials that never appear in prompts or model context.
Adaptive Security research reveals an 8-to-1 gap between shadow AI adoption and enterprise governance, with OAuth scopes representing the real data-exposure surface.
New cryptographic protocol binds credential validity to parent liveness proofs, achieving 90× faster revocation than OAuth 2.0 for AI agent swarms.
New arXiv paper quantifies overeager actions in coding agents like Claude Code, Codex CLI, and Gemini CLI on harmless tasks.
Over 233 malicious versions of popular Laravel-Lang PHP packages were injected with a credential-stealing backdoor via poisoned GitHub version tags targeting developer infrastructure.
New MDPI paper categorizes MCP server attack surfaces into LLM-passive and LLM-active frameworks across multiple platforms.
NVIDIA open-sources OpenShell, a sandboxed execution runtime for autonomous AI agents with declarative YAML policy enforcement.
New benchmark reveals that asking agents to seek clarification before acting increases prompt injection success from ~2% to ~35% across frontier models.
New paper shows injection detectors drop from 93.8% to 9.7% detection when payloads mimic target-domain vocabulary, revealing a systemic blind spot in multi-agent LLM security.
CISA added CVE-2025-34291, a critical origin validation error in the Langflow AI builder platform, to its Known Exploited Vulnerabilities catalog with a CVSS score of 9.4.
Splunk patches three vulnerabilities in its AI Toolkit, including CVE-2026-20238 allowing low-privilege attackers to bypass role-based access control and trigger DoS conditions.