Posts
High-signal AI/security/automation notes.
Hugging Face LeRobot — Critical Pickle Deserialization RCE (CVE-2026-25874)
Pipecat Voice Agent Framework — Pickle Deserialization RCE (CVE-2025-62373)
Critical RCE in Pipecat, the open-source Python framework for voice and multimodal AI agents, via insecure pickle deserialization in LivekitFrameSerializer.
T-MAP — Red-Teaming LLM Agents with Trajectory-aware Evolutionary Search
New arXiv paper introduces T-MAP, a red-teaming framework that achieves 57.8% attack success rate against frontier LLM agents through trajectory-aware evolutionary search in MCP environments.
TeamPCP — Claude Code Used to Publish Malicious SAP CAP npm Packages
Wiz — GitHub CVE-2026-3854 RCE via Single Git Push
Cisco — Claude Code memory poisoning enables persistent agent compromise
Cisco researchers demonstrated a memory poisoning attack against Claude Code that achieves persistent behavioral manipulation across all projects and sessions via npm supply-chain hooks.
Cursor AI Agent Deletes PocketOS Production Database in 9 Seconds
LiteLLM Pre-Auth SQL Injection Exploited Within 36 Hours
Critical pre-auth SQL injection in LiteLLM (CVE-2026-42208) was exploited within 36 hours of disclosure, enabling attackers to extract virtual API keys and provider credentials from the PostgreSQL backend.
vanna-ai — CVE-2026-6977 Improper Authorization in Legacy Flask API
Bitwarden CLI Compromised — Shai-Hulud Campaign Targets AI Coding Assistants
A malicious Bitwarden CLI package stole credentials from Claude, Cursor, Codex CLI, Kiro, and Aider configs — part of a broader Checkmarx supply chain campaign.
Foresiet — Meta AI Agent Hallucinates Permissions, Exposes Internal Data
An internal Meta AI agent hallucinated incorrect permission scopes and exposed headcount projections and unreleased product timelines — no external attacker involved.
Google — 32% Rise in Indirect Prompt Injection Attacks Found Across Public Web
Google researchers scanned billions of pages in Common Crawl and found a 32% increase in malicious indirect prompt injection attempts between November 2025 and February 2026, with data exfiltration and destructive payloads in the wild.
Mozilla — 271 Vulnerabilities Found in Firefox 150 by Claude Mythos Preview
OpenAI GPT-5.5 Launches With Agentic Safeguard Delays and Bio Bug Bounty
OpenAI releases GPT-5.5 rated High cybersecurity risk, delays API access pending agentic security measures, and launches a $25K bio jailbreak bounty.
OpenClaw — Three Flaws Enable Policy Bypass and API Credential Theft
OpenClaw versions before 2026.4.20 ship with three vulnerabilities that let prompt-injected models bypass gateway guardrails, evade restrictive tool policies, and steal MiniMax API keys via workspace .env files.
Vercel Breach Traced to Lumma Stealer via Roblox Cheats, CEO Cites AI-Accelerated Attackers
arXiv — Behavioral Transfer in AI Agents Reveals Privacy Risks at Scale
The DFIR Report — Bissa Scanner: AI-Assisted Mass Exploitation
The DFIR Report exposes Bissa Scanner, an operation using Claude Code and OpenClaw to automate React2Shell exploitation and harvest tens of thousands of credentials.