Posts
High-signal AI/security/automation notes.
Socket & StepSecurity — Malicious node-ipc npm Packages Steal Claude AI, Kiro IDE Credentials
Three malicious versions of the widely-used node-ipc npm package harvest 90 categories of developer and cloud credentials — including Claude AI and Kiro IDE settings — and exfiltrate via DNS TXT records to a fake Azure domain.
OpenAI Breached in TanStack Supply Chain — Code-Signing Certificates Rotated, macOS Users Must Update
OpenAI confirms two employee devices were compromised in the Mini Shai-Hulud TanStack supply-chain attack, forcing rotation of macOS code-signing certificates for ChatGPT, Codex, and Atlas apps.
VulnCheck — AI-Assisted Vulnerability Discovery Drives 563% CVE Surge Across Major Vendors
VulnCheck data shows massive year-over-year CVE increases across Chrome (+563%), GitHub (+476%), Mozilla (+157%), and Apache (+170%) — consistent with widespread adoption of AI models for vulnerability discovery.
Cisco — Foundry Security Spec Open-Sources Agentic AI Security Architecture
Cisco open-sources the Foundry Security Spec, a structured specification for securing AI agents, MCP servers, and skills with YARA, LLM-based, and behavioral analysis scanners across AWS, Azure, and GCP deployments.
CSO Online — Pen Tests: AI Security Flaws 2.5× More Severe Than Legacy Bugs
CrewAI — Four CVEs Chain Sandbox Escape to Cloud Takeover (VU#221883)
CERT/CC VU#221883 covers four CrewAI vulnerabilities that chain from prompt injection through sandbox escape, SSRF, and credential theft to full cloud account compromise.
CVE-2026-44246 — nnUNet GitHub Issue Triage Agent Vulnerable to Prompt Injection
The Register — Three MCP Database Server Flaws Discovered, One Unpatched
Security researcher Tomer Peled discloses three vulnerabilities in MCP servers for Apache Doris, Apache Pinot, and Alibaba RDS — with Alibaba declining to patch.
Microsoft — MDASH Agentic System Finds 16 Windows Flaws Including 4 Critical RCEs
Open WebUI — Path Traversal Arbitrary File Write/Delete (CVE-2026-44565, CVE-2026-44566)
OpenAI — Daybreak Initiative Expands Codex Security Into Enterprise Cybersecurity Platform
Palo Alto Networks — AI Models Drive Majority of Findings in May Patch Cycle
Palo Alto Networks reports that frontier AI models (Mythos, Opus 4.7, GPT-5.5-Cyber) produced the majority of vulnerability findings across 130+ products, yielding 26 CVEs vs. the usual <5 per month.
vm2 — Dozen Critical Sandbox Escape CVEs in Node.js Code Execution Library
Twelve sandbox escape vulnerabilities in the vm2 Node.js library (CVE-2026-24118 through CVE-2026-44009) threaten AI coding agents and code interpreters that rely on JS isolation.
Adversa AI TrustFall — Claude Code One-Click RCE
arXiv PinTrace — LLMs Systematically Pin Vulnerable Dependency Versions
A May 2026 study finds 37–56% of agent-generated Python code pins library versions with known critical CVEs — a systemic bias rooted in training data co-occurrence, not model-specific behavior.
Cline Kanban — Cross-Origin WebSocket Hijack → RCE (CVE-2026-44211)
The kanban npm package shipped with Cline CLI exposes three unauthenticated WebSocket endpoints on localhost; any website can hijack agent terminals and execute arbitrary commands.
DeepChat — CVE-2026-43899 RCE via Electron Pop-up Bypass & CVE-2026-43900 XSS
DeepChat, an open-source AI agent platform, ships with two critical vulnerabilities: an Electron pop-up bypass enabling RCE via malicious Markdown links (CVSS 9.6) and a stored XSS vulnerability.
Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads
Forcepoint researchers found 10 live indirect prompt injection payloads targeting AI agents, including financial fraud, API key theft, recursive file deletion, and attribution hijacking.