Posts
High-signal AI/security/automation notes.
The Register — Three MCP Database Server Flaws Discovered, One Unpatched
Security researcher Tomer Peled discloses three vulnerabilities in MCP servers for Apache Doris, Apache Pinot, and Alibaba RDS — with Alibaba declining to patch.
Microsoft — MDASH Agentic System Finds 16 Windows Flaws Including 4 Critical RCEs
Open WebUI — Path Traversal Arbitrary File Write/Delete (CVE-2026-44565, CVE-2026-44566)
OpenAI — Daybreak Initiative Expands Codex Security Into Enterprise Cybersecurity Platform
Palo Alto Networks — AI Models Drive Majority of Findings in May Patch Cycle
Palo Alto Networks reports that frontier AI models (Mythos, Opus 4.7, GPT-5.5-Cyber) produced the majority of vulnerability findings across 130+ products, yielding 26 CVEs vs. the usual <5 per month.
vm2 — Dozen Critical Sandbox Escape CVEs in Node.js Code Execution Library
Twelve sandbox escape vulnerabilities in the vm2 Node.js library (CVE-2026-24118 through CVE-2026-44009) threaten AI coding agents and code interpreters that rely on JS isolation.
Adversa AI TrustFall — Claude Code One-Click RCE
arXiv PinTrace — LLMs Systematically Pin Vulnerable Dependency Versions
A May 2026 study finds 37–56% of agent-generated Python code pins library versions with known critical CVEs — a systemic bias rooted in training data co-occurrence, not model-specific behavior.
Cline Kanban — Cross-Origin WebSocket Hijack → RCE (CVE-2026-44211)
The kanban npm package shipped with Cline CLI exposes three unauthenticated WebSocket endpoints on localhost; any website can hijack agent terminals and execute arbitrary commands.
DeepChat — CVE-2026-43899 RCE via Electron Pop-up Bypass & CVE-2026-43900 XSS
DeepChat, an open-source AI agent platform, ships with two critical vulnerabilities: an Electron pop-up bypass enabling RCE via malicious Markdown links (CVSS 9.6) and a stored XSS vulnerability.
Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads
Forcepoint researchers found 10 live indirect prompt injection payloads targeting AI agents, including financial fraud, API key theft, recursive file deletion, and attribution hijacking.
JunoClaw — Critical Mnemonic Exposure in Agentic AI Platform (CVE-2026-43992)
Langflow — Path Traversal in Knowledge Bases API (CVE-2026-42048)
Microsoft 365 Copilot — Three Critical Info Disclosure CVEs Patched
Microsoft patched three critical information disclosure vulnerabilities in M365 Copilot and Copilot Chat in Edge, all leveraging improper neutralization of special elements in AI output.
Miggo Security — Anthropic, Google, Microsoft Paid Bug Bounties for AI Agent Hijacks, No CVEs Issued
A researcher demonstrated prompt injection attacks that hijacked AI agents from Anthropic, Google, and Microsoft via GitHub Actions — all three companies paid bounties quietly but published no advisories or CVEs.
Mini Shai-Hulud — Self-Spreading Supply Chain Worm Hits 169 npm Packages, Mistral AI and UiPath
The Mini Shai-Hulud supply-chain worm has escalated to 169 npm packages and 373 malicious versions across @tanstack, @mistralai, @uipath, and now PyPI, with autonomous self-propagation via stolen OIDC tokens.
PraisonAI — CVE-2026-44338 Auth Bypass Exploited in Under 4 Hours
Adversa AI — IICL Attack Bypasses GPT-5.4 Safety at 60% Success Rate
Adversa AI researchers demonstrate Involuntary In-Context Learning (IICL), a novel technique that bypasses GPT-5.4 safety guardrails with 60% success rate using just 10 examples and 2 words.
arXiv — Response-Path Attacks on LLM Agents Outperform Prompt Injection
New research formalizes post-alignment tampering where adversarial relay services rewrite LLM responses before agent execution, achieving 99.1% attack success rate.