High-signal AI/security/automation notes.
Microsoft Defender for Cloud signals reveal 15% of remote MCP servers allow unauthenticated access, and default Kubernetes deployments of Mage AI expose admin UIs to the internet.
Three malicious versions of the widely-used node-ipc npm package harvest 90 categories of developer and cloud credentials — including Claude AI and Kiro IDE settings — and exfiltrate via DNS TXT records to a fake Azure domain.
OpenAI confirms two employee devices were compromised in the Mini Shai-Hulud TanStack supply-chain attack, forcing rotation of macOS code-signing certificates for ChatGPT, Codex, and Atlas apps.
VulnCheck data shows massive year-over-year CVE increases across Chrome (+563%), GitHub (+476%), Mozilla (+157%), and Apache (+170%) — consistent with widespread adoption of AI models for vulnerability discovery.
Cisco open-sources the Foundry Security Spec, a structured specification for securing AI agents, MCP servers, and skills with YARA, LLM-based, and behavioral analysis scanners across AWS, Azure, and GCP deployments.
CERT/CC VU#221883 covers four CrewAI vulnerabilities that chain from prompt injection through sandbox escape, SSRF, and credential theft to full cloud account compromise.
Security researcher Tomer Peled discloses three vulnerabilities in MCP servers for Apache Doris, Apache Pinot, and Alibaba RDS — with Alibaba declining to patch.
Palo Alto Networks reports that frontier AI models (Mythos, Opus 4.7, GPT-5.5-Cyber) produced the majority of vulnerability findings across 130+ products, yielding 26 CVEs vs. the usual <5 per month.
Twelve sandbox escape vulnerabilities in the vm2 Node.js library (CVE-2026-24118 through CVE-2026-44009) threaten AI coding agents and code interpreters that rely on JS isolation.
A May 2026 study finds 37–56% of agent-generated Python code pins library versions with known critical CVEs — a systemic bias rooted in training data co-occurrence, not model-specific behavior.
The kanban npm package shipped with Cline CLI exposes three unauthenticated WebSocket endpoints on localhost; any website can hijack agent terminals and execute arbitrary commands.
DeepChat, an open-source AI agent platform, ships with two critical vulnerabilities: an Electron pop-up bypass enabling RCE via malicious Markdown links (CVSS 9.6) and a stored XSS vulnerability.
Forcepoint researchers found 10 live indirect prompt injection payloads targeting AI agents, including financial fraud, API key theft, recursive file deletion, and attribution hijacking.