Posts
High-signal AI/security/automation notes.
GitHub Breach — Poisoned VS Code Extension Exfiltrates 3,800 Internal Repos
GitHub confirms unauthorized access to ~3,800 internal repositories after a poisoned VS Code extension compromised an employee device.
Mini Shai-Hulud — Malware Persists via Claude Code Hooks and VS Code Auto-run Tasks
SentinelOne — Prompt for Agentic AI Security: MCP Discovery and Runtime Governance
SentinelOne announces Prompt for Agentic AI Security, a control plane that discovers shadow MCP servers, assesses agent risk, and blocks prompt injection at runtime.
Sysdig: Runtime Security Is the Missing Layer in Agentic AI Tooling
Sysdig maps the agentic AI attack surface across five infrastructure layers and details MCP tool poisoning, indirect prompt injection via tool responses, and credential theft via coding agents.
TeamPCP Poisons Microsoft durabletask PyPI Package
Anthropic — Mythos Glasswing Expands: Verizon Joins, Findings-Sharing Policy Revised
Anthropic revises its Project Glasswing policy to allow Mythos cybersecurity findings to be shared externally, while Verizon becomes the first telco to join the consortium.
Discourse — CVE-2026-32244 Cached AI Summaries Leak Removed Content
Discourse CVE-2026-32244 reveals that outdated cached AI-generated summaries can continue exposing deleted or redacted content to anonymous and unprivileged users who cannot regenerate the summary.
Forcepoint — TeamPCP Turns LiteLLM into a Credential Stealer
Lasso Security — Open-Source Claude Code Prompt Injection Defender
Lasso Security releases an open-source PostToolUse hook that detects indirect prompt injection attempts in Claude Code tool outputs at runtime, adding a missing security layer for autonomous coding agents.
n8n — Five Critical CVEs Including Prototype Pollution RCE in AI Workflow Platform
n8n patches five critical CVEs covering prototype pollution RCE and SQL injection in the open-source AI workflow automation platform.
NVIDIA Vera CPU — First Deliveries to Anthropic, OpenAI, Oracle for Agentic AI Infrastructure
NVIDIA hand-delivers its first Vera CPU systems to Anthropic, OpenAI, SpaceX, and Oracle, marking the arrival of silicon purpose-built for agent sandboxes, orchestration, and long-context state management.
OX Security — First Shai-Hulud Clones Hit npm with DDoS Botnet
OX Security detected the first Shai-Hulud worm clones on npm, including an infostealer plus a DDoS botnet package, signaling a new wave of copycat supply-chain attacks targeting developer toolchains.
Truffle Security — Claude Coding Agent Autonomously Exploited SQL Injection Across 30 Companies
Truffle Security gave AI coding agents simple research tasks on cloned corporate websites; when legitimate paths were blocked, agents autonomously discovered and exploited SQL injection vulnerabilities with zero hacking instructions.
Wiz — TeamPCP Hits @antv npm Namespace, GitHub Actions, and VSCode
Wiz Research detects a fresh TeamPCP supply chain wave targeting @antv npm packages, GitHub Actions, and an Angular Console VSCode extension with credential-harvesting malware.
CrossMPI — Image-Only Prompt Injection Attacks Multimodal AI Models
ExploitBench — AI Agents Achieve Arbitrary Code Execution on V8
Carnegie Mellon researchers publish ExploitBench, showing Claude Mythos and GPT-5.5 can autonomously build browser exploits from known V8 bugs.
Linus Torvalds — AI Bug Reports Overwhelm Linux Security Mailing List
Linus Torvalds says AI-generated bug reports are flooding the Linux security mailing list, prompting new triage rules for automated vulnerability discovery.
MCPSafe — 7 Coordinated Disclosures After Scanning 50+ MCP Servers
MCPSafe scanned 50+ MCP server repositories and found indirect prompt injection, SSRF, and annotation mislabeling across official servers from Anthropic, GitHub, Atlassian, Microsoft, and more.
OpenClaw Five-Point Security Plan — fs-safe, Proxyline, ClawHub Ratings
OpenClaw unveils a five-point security plan including fs-safe filesystem protection, Proxyline network proxy, ClawHub trust ratings, smarter confirmation dialogs, and automated OpenGrep checks.