Bishop Fox — AIMap Open-Source AI Infrastructure Scanner
Bishop Fox releases AIMap, an open-source platform for discovering and attack-testing exposed AI agent infrastructure at internet scale.
High-signal AI/security/automation notes.
Bishop Fox releases AIMap, an open-source platform for discovering and attack-testing exposed AI agent infrastructure at internet scale.
A new supply chain campaign publishes sleeper packages across RubyGems and Go modules that harvest credentials, tamper with GitHub Actions, and plant SSH backdoors — with payloads impersonating Claude Code.
CISA, NSA, and four allied national cyber agencies publish joint guidance warning that agentic AI is already in critical infrastructure with insufficient safeguards, urging zero-trust and least-privilege controls.
CVE-2026-6543 is a critical command injection vulnerability in IBM Langflow Desktop (versions 1.0.0–1.8.4) allowing authenticated attackers to execute arbitrary OS commands — risking exposure of model API keys, agent configs, and RAG knowledge bases.
The popular PyTorch Lightning deep learning framework (31k+ GitHub stars) was compromised with credential-stealing malware in versions 2.6.2 and 2.6.3, part of the ongoing Mini Shai-Hulud campaign targeting AI infrastructure.
Six independent research teams demonstrated exploits against Codex, Claude Code, Copilot and Vertex AI — every single attack went for the credential, not the model.
Cequence Security released Agent Personas in its AI Gateway, solving the agent privilege escalation problem by mapping plain-English role descriptions to scoped virtual MCP endpoints.
University of Delaware researchers scanned 67,000+ MCP servers across six registries, revealing widespread server hijacking risks, tool metadata manipulation, and missing verification in MCP hosts.
MCPTox benchmark evaluates 20 LLM agents against tool poisoning attacks on 45 real MCP servers — o1-mini hit 72.8% success rate, with more capable models often more vulnerable.
The TeamPCP supply-chain operation expanded from SAP npm packages to PyPI (PyTorch Lightning) and intercom-client within 48 hours, targeting AI and ML developer ecosystems.
Novee researchers discovered a high-severity vulnerability in Cursor IDE (CVE-2026-26268, CVSS 8.1) where the AI coding agent autonomously triggers malicious Git hooks when opening attacker-controlled repositories.
NSFOCUS announced AI-Scan, a dedicated security scanner for the OpenClaw agent ecosystem covering CVE matching, credential leak detection, memory poisoning, and supply-chain risk.
New research proves embedding-based RAG defenses miss 79-90% of numerical manipulations — changing a tax figure by $50,000 yields 0.9998 cosine similarity, invisible to detection.
Wiz launches Red Agent for AI-driven vulnerability simulation, AI-BOM for framework inventory, and Wiz Code guardrails — expanding its AI Application Protection Platform from code to cloud edge.
Most AI security scanners only cover packaged dependencies, missing the dynamic components agents load at runtime — model adapters, MCP connections, and first-invocation tools.
A new benchmark tests five frontier LLMs on real-world threat hunting across 106 attack procedures — the best model flags only 3.8% of malicious events.
Four MCP trust boundaries — permissions, tools, inputs, and observability — that teams are getting wrong when connecting AI agents to real systems.