Cloudflare Precursor Moves Agent Detection From Requests to Full Sessions
Cloudflare’s Precursor continuously evaluates browser behavior across a session, feeding agent and bot signals into bot scores, challenges, analytics, and WAF policy.
High-signal AI/security/automation notes.
Cloudflare’s Precursor continuously evaluates browser behavior across a session, feeding agent and bot signals into bot scores, challenges, analytics, and WAF policy.
UMKC researchers demonstrate Ghostcommit, a pull-request attack that hides prompt injection in a PNG, bypasses text-only review, and makes coding agents encode .env secrets into source code.
UC Berkeley researchers propose Prismata, a DOM-aware least-privilege layer that confines web agents and sharply reduces cross-site prompt-injection success in WebArena tests.
AWS patched CVE-2026-14471, a high-severity authenticated SQL injection in MCP Gateway Registry versions 1.0.3 through 1.0.12 that can expose API key material.
Google has put Cloud Run sandboxes into public preview, adding credential isolation, default-deny network egress, and disposable filesystem overlays for AI-generated code.
Tongji researchers propose SpellSmith, a text-based mitigation that embeds behavioral guardrails into MCP tool descriptions to block taint-style exploits without code-level patches.
Three high-severity vulnerabilities in OpenClaw let attackers chain environment variable injection, git transport abuse, and Docker sandbox escape to achieve host-level code execution via WhatsApp messages.
Tel Aviv University researchers demonstrate how attackers can weaponize LLM hallucinations to establish agentic botnets, achieving 100% attack success against multiple AI coding assistants.
CrowdStrike expands its prompt injection taxonomy to over 200 techniques, revealing how attacks against AI agents are fragmenting into composite chains.
Palo Alto Networks Unit 42 disclosed a critical vulnerability in Google Cloud Vertex AI SDK that allowed cross-tenant model poisoning and remote code execution via bucket squatting.
CISA adds Langflow CVE-2026-55255 to its Known Exploited Vulnerabilities catalog — the first AI agent orchestration platform ever listed — with a July 10 deadline.
New research demonstrates workflow-level jailbreak construction: coding agents that refuse harmful prompts in chat will produce the same harmful content when asked to write it as code.
The EU published an Action Plan on July 7, 2026 to address risks and opportunities of advanced AI for cybersecurity, including AI model evaluation, structured access, and secure testing platforms.
Fiddler AI maps the full coding-agent attack surface — prompt injection, supply-chain poisoning, credential leaks, MCP spoofing — and proposes runtime guardrails.
Sygnia reports a single threat actor used agentic AI workflows to execute a full cloud compromise in 72 hours — a campaign that would have taken weeks manually.