Posts
High-signal AI/security/automation notes.
Trump Scraps AI Executive Order on Frontier Model Oversight
Trump abruptly postponed a planned AI executive order that would have required pre-deployment government review of frontier models, after pressure from tech leaders.
WordPress 7.0 — AI Agent Infrastructure and API Key Theft Risk
WordPress 7.0 ships AI client, Connectors API, Abilities API, and an MCP adapter, centralizing high-value API keys across 43% of the web.
arXiv: AI Agents May Always Fall for Prompt Injections
New arXiv paper recasts prompt injection through Contextual Integrity theory, demonstrating an impossibility result: any defense tight enough to block attacks will also break legitimate agent workflows.
arXiv — Securing LLM Agents Needs Intent-to-Execution Integrity (2605.16976)
NUS/UCLA/Berkeley researchers propose intent-to-execution integrity as a correctness property for LLM agent security, analyzing defense gaps in systems like OpenClaw, NemoClaw, and SeClaw.
arXiv: Remembering More, Risking More — Longitudinal Safety in Memory Agents
New arXiv paper shows memory-equipped LLM agents accumulate risk over time as stored content contaminates future decisions, even across unrelated tasks.
CSA Research Note: MCP Security Crisis — Systemic Design Flaws in AI Agent Infrastructure
Nebula Security — Vega AI Discovers nginx-poolslip Zero-Day RCE in Patched nginx 1.31.0
An autonomous AI security agent Vega found a second unpatched RCE in nginx 1.31.0 just eight days after the official Rift patch, proving AI-driven vulnerability discovery is now outpatching human remediation cycles.
Pydantic AI — SSRF Cloud-Metadata Blocklist Bypass via IPv6
SGLang Three Unauthenticated RCEs (CVE-2026-7301/7302/7304)
Spring AI MCP — SSRF via Dynamic Client Registration
Anthropic Silently Patches Claude Code Sandbox Bypass
A second network sandbox bypass in Claude Code, patched silently in April 2026 with no CVE, exposed credentials and source code for over five months.
ChromaDB CVE-2026-45829 — Unpatched RCE in Vector Database
Microsoft Defender Guide — Memory Poisoning, Jailbreaks, Evasion for AI Agents
Microsoft Open-Sources RAMPART and Clarity for AI Agent Security
Microsoft released two open-source tools to shift AI safety testing from post-build red team reviews to in-development, living security artifacts.
NVIDIA Triton — CVE-2026-24207 Critical Auth Bypass in Inference Server
NVIDIA shipped a patch for CVE-2026-24207 (CVSS 9.8), an authentication bypass in Triton Inference Server that requires zero credentials and enables remote code execution on model-serving endpoints.
Verizon DBIR 2026 — Exploitation Tops Credential Abuse, AI Shrinks Defense Windows
arXiv Survey: Agentic AI in IT Ops Faces the Classic Confused-Deputy Problem
A new arXiv survey maps four attack categories targeting LLM-driven operations agents and proposes a propose-commit architectural split as the core defense.
arXiv: AI Agents May Always Fall for Prompt Injections
New arXiv paper proves prompt injection is fundamentally unsolvable for autonomous agents, achieving 96.7% attack success via contextual manipulation against frontier models.
arXiv: Semantic Compliance Hijacking — Payload-less Skill Attacks on AI Agents
New research demonstrates payload-less supply-chain attacks against AI agents via Semantic Compliance Hijacking, achieving 77.7% confidentiality breach and 67.3% RCE with 0% detection rate.