Posts
High-signal AI/security/automation notes.
Anthropic — Mythos Glasswing Expands: Verizon Joins, Findings-Sharing Policy Revised
Anthropic revises its Project Glasswing policy to allow Mythos cybersecurity findings to be shared externally, while Verizon becomes the first telco to join the consortium.
Discourse — CVE-2026-32244 Cached AI Summaries Leak Removed Content
Discourse CVE-2026-32244 reveals that outdated cached AI-generated summaries can continue exposing deleted or redacted content to anonymous and unprivileged users who cannot regenerate the summary.
Forcepoint — TeamPCP Turns LiteLLM into a Credential Stealer
Lasso Security — Open-Source Claude Code Prompt Injection Defender
Lasso Security releases an open-source PostToolUse hook that detects indirect prompt injection attempts in Claude Code tool outputs at runtime, adding a missing security layer for autonomous coding agents.
n8n — Five Critical CVEs Including Prototype Pollution RCE in AI Workflow Platform
n8n patches five critical CVEs covering prototype pollution RCE and SQL injection in the open-source AI workflow automation platform.
NVIDIA Vera CPU — First Deliveries to Anthropic, OpenAI, Oracle for Agentic AI Infrastructure
NVIDIA hand-delivers its first Vera CPU systems to Anthropic, OpenAI, SpaceX, and Oracle, marking the arrival of silicon purpose-built for agent sandboxes, orchestration, and long-context state management.
OX Security — First Shai-Hulud Clones Hit npm with DDoS Botnet
OX Security detected the first Shai-Hulud worm clones on npm, including an infostealer plus a DDoS botnet package, signaling a new wave of copycat supply-chain attacks targeting developer toolchains.
Truffle Security — Claude Coding Agent Autonomously Exploited SQL Injection Across 30 Companies
Truffle Security gave AI coding agents simple research tasks on cloned corporate websites; when legitimate paths were blocked, agents autonomously discovered and exploited SQL injection vulnerabilities with zero hacking instructions.
Wiz — TeamPCP Hits @antv npm Namespace, GitHub Actions, and VSCode
Wiz Research detects a fresh TeamPCP supply chain wave targeting @antv npm packages, GitHub Actions, and an Angular Console VSCode extension with credential-harvesting malware.
CrossMPI — Image-Only Prompt Injection Attacks Multimodal AI Models
ExploitBench — AI Agents Achieve Arbitrary Code Execution on V8
Carnegie Mellon researchers publish ExploitBench, showing Claude Mythos and GPT-5.5 can autonomously build browser exploits from known V8 bugs.
Linus Torvalds — AI Bug Reports Overwhelm Linux Security Mailing List
Linus Torvalds says AI-generated bug reports are flooding the Linux security mailing list, prompting new triage rules for automated vulnerability discovery.
MCPSafe — 7 Coordinated Disclosures After Scanning 50+ MCP Servers
MCPSafe scanned 50+ MCP server repositories and found indirect prompt injection, SSRF, and annotation mislabeling across official servers from Anthropic, GitHub, Atlassian, Microsoft, and more.
OpenClaw Five-Point Security Plan — fs-safe, Proxyline, ClawHub Ratings
OpenClaw unveils a five-point security plan including fs-safe filesystem protection, Proxyline network proxy, ClawHub trust ratings, smarter confirmation dialogs, and automated OpenGrep checks.
Pwn2Own Berlin 2026 — OpenAI Codex Exploited, $1.29M in 47 Zero-Days
Pwn2Own Berlin 2026 concluded with $1.29M awarded for 47 zero-days, including a successful exploit against OpenAI Codex AI coding assistant.
arXiv — MATRA Threat Modeling Framework for Agentic AI Systems
MITRE researchers present MATRA, a pragmatic threat modeling framework that adapts established risk assessment methodology to quantify agentic AI deployment risks using OpenClaw as a case study.
arXiv — Securing AI Agents Like Operating Systems
Researchers argue that LLM-based agents face the same isolation, privilege separation, and communication mediation challenges as operating systems, and demonstrate that many protection mechanisms fail in practice.
arXiv — Security Risks in Tool-Enabled AI Agents in Privileged Cloud Environments
IEEE COMPSAC 2026 short paper analyzes security risks of cloud-hosted AI agents, finding that most risks arise not from novel vulnerabilities but from over-privileged tools, capability-intent mismatches, and ambient authority leakage.
Cymulate — Prompt Injection Triggers Zero-Click RCE in AI CLI Tools (Cursor, Kiro, Codex, Gemini)
Cymulate researchers uncovered zero-click RCE chains across Cursor CLI, AWS Kiro, Codex Desktop, and Gemini CLI — where a single prompt injection can silently execute code via Windows PATH hijacking and config file poisoning.