Posts
High-signal AI/security/automation notes.
Adversa AI — IICL Attack Bypasses GPT-5.4 Safety at 60% Success Rate
Adversa AI researchers demonstrate Involuntary In-Context Learning (IICL), a novel technique that bypasses GPT-5.4 safety guardrails with 60% success rate using just 10 examples and 2 words.
arXiv — Response-Path Attacks on LLM Agents Outperform Prompt Injection
New research formalizes post-alignment tampering where adversarial relay services rewrite LLM responses before agent execution, achieving 99.1% attack success rate.
CISA KEV — LiteLLM CVE-2026-42208 SQL Injection Under Active Exploitation
CISA added the critical LiteLLM proxy SQL injection flaw to its Known Exploited Vulnerabilities catalog, confirming in-the-wild exploitation that can expose AI deployment credentials.
Google GTIG — AI-Assisted Zero-Day 2FA Bypass for Mass Exploitation
Google Threat Intelligence Group reports hackers used AI to discover and weaponize a zero-day 2FA bypass, the first confirmed case of AI-assisted exploit development for mass exploitation.
OpenClaw — CVE-2026-44995 MCP Stdio Server Environment Variable RCE
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code.
OWASP MCP Top 10 — 38% of MCP Servers Have No Authentication, 30+ CVEs in 60 Days
OWASP publishes the MCP Top 10 revealing 38% of scanned MCP servers lack authentication, 30+ CVEs filed in 60 days, and a STDIO RCE affecting every official MCP SDK.
Slopsquatting — LLM-Hallucinated Package Names Create New Supply Chain Attack Vector
Security researcher registers NPM packages matching names AI coding agents hallucinate, proving a new supply-chain attack primitive where agents auto-install attacker-controlled dependencies.
TeamPCP — Re-Compromises Checkmarx Jenkins AST Plugin Weeks After Initial Breach
TeamPCP breached Checkmarx a second time, backdooring the Jenkins AST plugin just weeks after the initial KICS and VS Code compromise, suggesting incomplete remediation or a retained foothold.
Acronis TRU: 575+ Malicious AI Skills on ClawHub and Hugging Face Deploy Malware
Acronis TRU identified 575+ malicious OpenClaw skills across 13 accounts and Hugging Face repositories used as multi-stage infection chains for trojans, cryptominers, and infostealers.
ClaudeBleed: Chrome Extension Flaw Allows AI Agent Takeover via Prompt Injection
LayerX discovered a Chrome extension vulnerability (ClaudeBleed) that lets any extension hijack Claude in Chrome for data exfiltration, email abuse, and document sharing.
Five Eyes — Joint Guidance Warns Agentic AI Is Too Dangerous for Rapid Rollout
CISA, NSA, NCSC-UK, NCSC-NZ, Canadian Cyber Centre, and ASD/ACSC co-authored guidance urging slow, careful adoption of agentic AI, warning that the interconnected attack surface amplifies organizational security gaps.
Grok/Bankrbot Morse Code Prompt Injection Drains $150K Crypto Wallet
SecurityScorecard — Tens of Thousands of Exposed OpenClaw Instances, 35% RCE-vulnerable
ThreatLabz — Malicious OpenClaw Skill Distributes Remcos RAT and GhostLoader
Zscaler ThreatLabz details a supply-chain campaign where a deceptive OpenClaw skill delivers Remcos RAT on Windows and GhostLoader stealer on macOS/Linux via hidden installer commands.
VentureBeat — AI Tool Poisoning Exposes the Behavioral Integrity Gap in Agent Registries
banks CVE-2026-44209 — Jinja2 SSTI in Prompt Template Library Leads to RCE
PyPI prompt template library banks <= 2.4.1 uses unsandboxed Jinja2, allowing Server-Side Template Injection and full RCE when user-supplied templates reach Prompt().