High-signal AI/security/automation notes.
Axis Intelligence tested 312 LLM attack vectors against six production models — 71% succeeded against at least one, 23% against all six, and system-prompt extraction works in 31% of deployments.
CrowdStrike, Google and Shadowserver simultaneously disrupt all four C2 channels of the GlassWorm malware campaign that has poisoned 300+ GitHub repos since 2025.
Two 2026 reports reveal that 88% of AI agent operators have already experienced security incidents, 63% cannot enforce purpose limits on agents, and 60% cannot terminate misbehaving agents.
Perplexity open-sources Bumblebee, a read-only Go scanner that inventories developer machines for compromised npm, PyPI, Go modules and MCP configurations.
A single-character Host header flaw in Starlette bypasses authentication in thousands of FastAPI-based AI tools, model proxies, and MCP servers.
SymJack turns AI coding agents into supply-chain delivery systems: disguised symlinks inject malicious MCP servers that run unsandboxed on developer restart.
Anthropic releases a free security-guidance plugin for Claude Code that runs deterministic pattern matching, a separate-model review, and agentic commit-time checks.
New research demonstrates that attacker-controlled log fields (URLs, user agents, payloads) can carry prompt injection attacks into LLM-based security operations center tools, with persona hijacks bypassing 68% of triage alerts.
IRGC-affiliated Nimbus Manticore group deploys AI-assisted malware toolkit MiniFast targeting defense, aerospace, and telecom sectors.
Three chained vulnerabilities in Claude.ai — invisible prompt injection via URL parameters, Files API data exfiltration, and an open redirect — create a complete attack pipeline against millions of users.
Phishing campaigns use zero-font and color-matched hidden text to inject benign content that tricks AI email filters into classifying malicious messages as safe.
PromptArmor demonstrated that weaponized workflow content can force Copilot Cowork to generate and share Microsoft 365 file links to unauthorized recipients, completely bypassing user consent.
A single-character Host header injection in Starlette (325M weekly downloads) bypasses path-based auth in FastAPI, vLLM, LiteLLM, and MCP servers, exposing credentials and PII across millions of AI agent deployments.
A new arXiv paper proposes mcp-attested: a signed clearance assertion, per-server tool allowlist, and tamper-evident audit log for MCP deployments.
INFRASCOPE uses reference-driven multi-agent analysis to find recurring vulnerability patterns across 688 AI infrastructure repositories, uncovering 20+ new vulnerabilities.
First measurement study of 7,973 live remote MCP servers finds over 40% expose tools without authentication; OAuth deployments universally exhibit at least one flaw, yielding 9 CVEs.