Posts
High-signal AI/security/automation notes.
Sygnia — Lone Attacker Uses Agentic AI to Compromise AWS in 72 Hours
Sygnia reports a single threat actor used agentic AI workflows to execute a full cloud compromise in 72 hours — a campaign that would have taken weeks manually.
TeamPCP — Supply Chain Compromise of Trivy, LiteLLM, and KICS Feeds VECT Ransomware Credential Archive
TeamPCP poisoned Trivy, Checkmarx KICS, LiteLLM, and Telnyx SDK to harvest 500K+ CI/CD credentials — VECT ransomware then selected victims from the archive.
arXiv — Agent Data Injection (ADI): New IPI Category Bypasses All Defenses
Seoul National University and UIUC researchers introduce Agent Data Injection, a new class of indirect prompt injection that exploits lack of trusted/untrusted data isolation in LLM agents.
CVE-2026-59707 — LocalAI Unauthenticated SSRF in Model Apply Endpoint
LocalAI before the latest patch contains an unauthenticated SSRF vulnerability in POST /models/apply that allows attackers to fetch arbitrary internal URLs.
GitLost — GitHub Agentic Workflows Leak Private Repos via Prompt Injection
Noma Labs discovered GitLost, a critical indirect prompt injection in GitHub Agentic Workflows that lets unauthenticated attackers exfiltrate private repository content.
Langroid CVE-2026-55615 — Prompt-to-Cypher Injection Enables RCE via Neo4j
vLLM Patches Two New DoS CVEs in v0.24.0 — Audio Memory Exhaustion and Regex ReDoS
CVE-2026-55646 lets unauthenticated API callers exhaust memory via oversized audio uploads; CVE-2026-55574 enables indefinite inference worker hangs via adversarial regex patterns.
vLLM CVE-2026-55646 — Audio Upload Memory Exhaustion DoS (CVSS 6.5)
vLLM speech-to-text endpoints allocate full upload before enforcing audio file-size limit, enabling remote memory exhaustion DoS. Fixed in 0.24.0.
Zscaler — Indirect Prompt Injection Tricks AI Agents Into Crypto Payments
Two campaigns use SEO poisoning and indirect prompt injection to manipulate AI agents into making cryptocurrency payments or trusting fraudulent DeFi platforms.
AI Bug Hunting Drives Record CVE Spike — 1,500 High-Severity Flaws in June 2026
June 2026 set a record for high- and top-severity CVEs among 21 notable organizations, driven by AI-powered vulnerability discovery tools like Claude Mythos and GPT-5.5-Cyber.
FatFs: LLM-Assisted Fuzzing Finds 7 CVEs in Embedded Firmware
runZero researchers used GitHub Copilot to fuzz FatFs, a compact C library for FAT/exFAT media parsing, discovering 7 CVEs affecting IoT devices, drones, ATMs, and voting machines.
Microsoft Execution Containers (MXC) — Sandboxing AI Agents on Windows
Microsoft introduces Execution Containers (MXC), a new security layer for containing AI agent workflows on Windows with policy-driven isolation and identity enforcement.
NVIDIA Releases SkillSpector — Open-Source Scanner for AI Agent Skills
NVIDIA open-sourced SkillSpector, a security scanner that detects vulnerabilities, malicious patterns, and supply-chain risks in AI agent skills before installation.
TrendAI Audit Finds 4,982 Security Flaws Across 2,259 Public MCP Servers
TrendAI analysis of 9,695 MCP servers found 4,982 security issues across 2,259 servers, debunking assumptions about popularity and verification badges.
Vercel Breach: Shadow AI Tool Becomes Identity-Based Supply Chain Pivot
Adversa AI — 27 Agentic AI Security Resources for July 2026
Check Point — Critical Vulnerability Exposures Double in 2026, AI-Driven Triage Urgent
China — AI Companion Regulation Forces ByteDance and Alibaba to Kill Agent Features
CMU — FLARE-AI Open-Source Platform for Cross-Platform AI Vulnerability Reporting
CMU SEI launches FLARE-AI, an open-source platform that routes AI flaw reports to vendors, CERT/CC, and government agencies for coordinated disclosure.