Posts
High-signal AI/security/automation notes.
Anthropic Silently Patches Claude Code Sandbox Bypass
A second network sandbox bypass in Claude Code, patched silently in April 2026 with no CVE, exposed credentials and source code for over five months.
ChromaDB CVE-2026-45829 — Unpatched RCE in Vector Database
Microsoft Defender Guide — Memory Poisoning, Jailbreaks, Evasion for AI Agents
Microsoft Open-Sources RAMPART and Clarity for AI Agent Security
Microsoft released two open-source tools to shift AI safety testing from post-build red team reviews to in-development, living security artifacts.
NVIDIA Triton — CVE-2026-24207 Critical Auth Bypass in Inference Server
NVIDIA shipped a patch for CVE-2026-24207 (CVSS 9.8), an authentication bypass in Triton Inference Server that requires zero credentials and enables remote code execution on model-serving endpoints.
Verizon DBIR 2026 — Exploitation Tops Credential Abuse, AI Shrinks Defense Windows
arXiv Survey: Agentic AI in IT Ops Faces the Classic Confused-Deputy Problem
A new arXiv survey maps four attack categories targeting LLM-driven operations agents and proposes a propose-commit architectural split as the core defense.
arXiv: AI Agents May Always Fall for Prompt Injections
New arXiv paper proves prompt injection is fundamentally unsolvable for autonomous agents, achieving 96.7% attack success via contextual manipulation against frontier models.
arXiv: Semantic Compliance Hijacking — Payload-less Skill Attacks on AI Agents
New research demonstrates payload-less supply-chain attacks against AI agents via Semantic Compliance Hijacking, achieving 77.7% confidentiality breach and 67.3% RCE with 0% detection rate.
Cloudflare — Project Glasswing: What Mythos Found Across 50+ Repositories
GitHub Breach — Poisoned VS Code Extension Exfiltrates 3,800 Internal Repos
GitHub confirms unauthorized access to ~3,800 internal repositories after a poisoned VS Code extension compromised an employee device.
Mini Shai-Hulud — Malware Persists via Claude Code Hooks and VS Code Auto-run Tasks
SentinelOne — Prompt for Agentic AI Security: MCP Discovery and Runtime Governance
SentinelOne announces Prompt for Agentic AI Security, a control plane that discovers shadow MCP servers, assesses agent risk, and blocks prompt injection at runtime.
Sysdig: Runtime Security Is the Missing Layer in Agentic AI Tooling
Sysdig maps the agentic AI attack surface across five infrastructure layers and details MCP tool poisoning, indirect prompt injection via tool responses, and credential theft via coding agents.
TeamPCP Poisons Microsoft durabletask PyPI Package
Anthropic — Mythos Glasswing Expands: Verizon Joins, Findings-Sharing Policy Revised
Anthropic revises its Project Glasswing policy to allow Mythos cybersecurity findings to be shared externally, while Verizon becomes the first telco to join the consortium.
Discourse — CVE-2026-32244 Cached AI Summaries Leak Removed Content
Discourse CVE-2026-32244 reveals that outdated cached AI-generated summaries can continue exposing deleted or redacted content to anonymous and unprivileged users who cannot regenerate the summary.
Forcepoint — TeamPCP Turns LiteLLM into a Credential Stealer
Lasso Security — Open-Source Claude Code Prompt Injection Defender
Lasso Security releases an open-source PostToolUse hook that detects indirect prompt injection attempts in Claude Code tool outputs at runtime, adding a missing security layer for autonomous coding agents.