Posts
High-signal AI/security/automation notes.
banks CVE-2026-44209 — Jinja2 SSTI in Prompt Template Library Leads to RCE
PyPI prompt template library banks <= 2.4.1 uses unsandboxed Jinja2, allowing Server-Side Template Injection and full RCE when user-supplied templates reach Prompt().
Oasis Security — Cline Kanban WebSocket Hijack (CVSS 9.7)
CVE-2026-44843 — LangChain Unsafe Deserialization via Overly Broad load() Allowlists
Dragos & Gambit — AI-Assisted OT Intrusion Against Mexican Water Utility
FastGPT CVE-2026-42302 — Agent Sandbox RCE via Disabled Authentication
CVE-2026-34070 — LangChain Path Traversal in Legacy Prompt Template Loading
Anthropic — Fed Chair and Treasury Convene Bank CEOs Over Mythos Cyber Risk
Federal Reserve and Treasury officials warned bank CEOs about automated zero-day discovery after Claude Mythos found thousands of flaws — as Bloomberg reports unauthorized access via a contractor account.
Pillar Security — Gemini CLI "TrustIssues" CVSS 10 Supply-Chain Compromise
Postiz CVE-2026-42298 — "Pwn Request" RCE in AI Social Media Scheduler via GitHub Actions
CVSS 10.0 RCE in Postiz, an AI social media scheduling tool: a malicious PR Dockerfile triggers code execution in GitHub Actions and exfiltrates a write-all GITHUB_TOKEN.
RSAC 2026 — Agent Identity Gap: When Valid Credentials Are Not Enough
VentureBeat — CLI-Anything AI Agent Skill Backdoor and Structural Supply-Chain Gap
CLI-Anything auto-generates AI agent skill files (SKILL.md) that no SAST or SCA scanner can detect, creating a new supply-chain attack surface across all major coding agents.
FastGPT — SSRF Cluster in AI Agent Platform
Four SSRF-related CVEs disclosed in FastGPT, an open-source AI agent platform: unauthenticated SSRF, MCP tool URL bypass, DNS rebinding, and inconsistent SSRF protection.
Forcepoint — 10 In-the-Wild Indirect Prompt Injection Payloads Targeting AI Agents
Forcepoint researchers discovered 10 real-world indirect prompt injection payloads hidden in web content, targeting AI agents for financial fraud, data destruction, and API key theft.
Jeff Kaufman — AI Is Breaking Two Vulnerability Disclosure Cultures
MCPwn — First Named MCP Exploit Campaigns with Actively Exploited CVEs
Pluto Security disclosed MCPwn (CVE-2026-33032, CVSS 9.8, actively exploited, 2,600+ instances exposed) and MCPwnfluence (CVE-2026-27825/27826, unauthenticated RCE via SSRF + arbitrary file write in mcp-atlassian).
Noma Security — MCP Servers and Skills: The Observability Gap in AI Agent Deployments
Noma Security analyzed hundreds of MCP servers and Skills: one in four MCP servers expose agents to code execution risk, and real-world attack chains like ContextCrush and ForcedLeak are already active.
Vercel Breached via Context AI Supply Chain — Internal Database Sold for $2M
Anthropic — Natural Language Autoencoders Reveal Models Can Detect Safety Tests
EU AI Act Simplification — Nudification Ban Enacted, High-Risk Rules Delayed
European lawmakers agreed to ban AI nudification tools while delaying high-risk AI enforcement to December 2027, reshaping the AI Act compliance timeline.