High-signal AI/security/automation notes.
TeamPCP poisoned Trivy, Checkmarx KICS, LiteLLM, and Telnyx SDK to harvest 500K+ CI/CD credentials — VECT ransomware then selected victims from the archive.
Seoul National University and UIUC researchers introduce Agent Data Injection, a new class of indirect prompt injection that exploits lack of trusted/untrusted data isolation in LLM agents.
LocalAI before the latest patch contains an unauthenticated SSRF vulnerability in POST /models/apply that allows attackers to fetch arbitrary internal URLs.
Noma Labs discovered GitLost, a critical indirect prompt injection in GitHub Agentic Workflows that lets unauthenticated attackers exfiltrate private repository content.
CVE-2026-55646 lets unauthenticated API callers exhaust memory via oversized audio uploads; CVE-2026-55574 enables indefinite inference worker hangs via adversarial regex patterns.
vLLM speech-to-text endpoints allocate full upload before enforcing audio file-size limit, enabling remote memory exhaustion DoS. Fixed in 0.24.0.
Two campaigns use SEO poisoning and indirect prompt injection to manipulate AI agents into making cryptocurrency payments or trusting fraudulent DeFi platforms.
June 2026 set a record for high- and top-severity CVEs among 21 notable organizations, driven by AI-powered vulnerability discovery tools like Claude Mythos and GPT-5.5-Cyber.
runZero researchers used GitHub Copilot to fuzz FatFs, a compact C library for FAT/exFAT media parsing, discovering 7 CVEs affecting IoT devices, drones, ATMs, and voting machines.
Microsoft introduces Execution Containers (MXC), a new security layer for containing AI agent workflows on Windows with policy-driven isolation and identity enforcement.
NVIDIA open-sourced SkillSpector, a security scanner that detects vulnerabilities, malicious patterns, and supply-chain risks in AI agent skills before installation.
TrendAI analysis of 9,695 MCP servers found 4,982 security issues across 2,259 servers, debunking assumptions about popularity and verification badges.
CMU SEI launches FLARE-AI, an open-source platform that routes AI flaw reports to vendors, CERT/CC, and government agencies for coordinated disclosure.
The IMA attack framework achieves 89% jailbreak success against MetaGPT, CrewAI, and other multi-agent systems by exploiting collaboration dynamics that amplify harm over single-agent baselines.