Pwn2Own Berlin 2026 — OpenAI Codex Exploited, $1.29M in 47 Zero-Days
Pwn2Own Berlin 2026 concluded with $1.29M awarded for 47 zero-days, including a successful exploit against OpenAI Codex AI coding assistant.
High-signal AI/security/automation notes.
Pwn2Own Berlin 2026 concluded with $1.29M awarded for 47 zero-days, including a successful exploit against OpenAI Codex AI coding assistant.
MITRE researchers present MATRA, a pragmatic threat modeling framework that adapts established risk assessment methodology to quantify agentic AI deployment risks using OpenClaw as a case study.
Researchers argue that LLM-based agents face the same isolation, privilege separation, and communication mediation challenges as operating systems, and demonstrate that many protection mechanisms fail in practice.
IEEE COMPSAC 2026 short paper analyzes security risks of cloud-hosted AI agents, finding that most risks arise not from novel vulnerabilities but from over-privileged tools, capability-intent mismatches, and ambient authority leakage.
Cymulate researchers uncovered zero-click RCE chains across Cursor CLI, AWS Kiro, Codex Desktop, and Gemini CLI — where a single prompt injection can silently execute code via Windows PATH hijacking and config file poisoning.
Greg KH and the oss-sec mailing list clarify that EU Cyber Resilience Act Article 14 vulnerability reporting obligations for AI manufacturers take effect September 11, 2026.
Forcepoint researchers found 10 real indirect prompt injection payloads hidden on live websites that instruct AI agents to delete files, steal API keys, and process fraudulent payments.
Security researcher Tomer Peled found three critical MCP server vulnerabilities affecting Apache Doris, Pinot, and Alibaba RDS — including SQL injection and metadata exfiltration — with one vendor declining to patch.
A 13-file Python toolkit deployed by TeamPCP after npm/PyPI supply chain compromises uses a 3-tier exfiltration chain, a GitHub commit-based dead-drop (FIRESCALE), and targets AWS GovCloud credentials.
New VectorSmuggle framework demonstrates how attackers can hide arbitrary data inside vector embeddings using steganography, bypassing DLP tools and vector database security checks.
New ICML 2026 paper proposes injecting noise into token embeddings to re-activate LLM safety safeguards, effectively detecting jailbreak prompts by testing their inherent fragility.
Cyera disclosed four chainable vulnerabilities in OpenClaw (CVSS 7.7–9.6), including a critical sandbox escape and privilege escalation, affecting 245K publicly exposed AI agent deployments.
Google Threat Intelligence Group reveals PROMPTSPY malware that uses embedded LLMs to interpret system states and dynamically generate commands, signaling a shift toward autonomous attack orchestration.
CVSS 8.6 auth bypass in mlflow ≤3.9.0 allows unauthenticated access to job submission and OpenTelemetry trace injection when served via uvicorn with basic-auth enabled.
A CVSS 8.6 SSRF in self-hosted Next.js via crafted WebSocket upgrades threatens thousands of AI-coded apps that ship Next.js as the default frontend — unauthenticated, no login required.
TeamPCP is selling ~450 Mistral AI repositories (5 GB of internal source code) for $25,000 on a hacker forum, threatening to leak the data publicly if no buyer is found within a week.
TeamPCP released the Shai-Hulud supply-chain worm source code publicly and launched a $1K BreachForums bounty for new package compromises, dramatically lowering the barrier for copycat attacks.
UK AI Safety Institute re-tests a newer Mythos Preview checkpoint: it solves two cyber ranges including one previously unsolved, and updates its doubling-rate estimate to 4.7 months for AI cyber capability growth.