High-signal AI/security/automation notes.
New ICML 2026 paper proposes injecting noise into token embeddings to re-activate LLM safety safeguards, effectively detecting jailbreak prompts by testing their inherent fragility.
Cyera disclosed four chainable vulnerabilities in OpenClaw (CVSS 7.7–9.6), including a critical sandbox escape and privilege escalation, affecting 245K publicly exposed AI agent deployments.
Google Threat Intelligence Group reveals PROMPTSPY malware that uses embedded LLMs to interpret system states and dynamically generate commands, signaling a shift toward autonomous attack orchestration.
CVSS 8.6 auth bypass in mlflow ≤3.9.0 allows unauthenticated access to job submission and OpenTelemetry trace injection when served via uvicorn with basic-auth enabled.
A CVSS 8.6 SSRF in self-hosted Next.js via crafted WebSocket upgrades threatens thousands of AI-coded apps that ship Next.js as the default frontend — unauthenticated, no login required.
TeamPCP is selling ~450 Mistral AI repositories (5 GB of internal source code) for $25,000 on a hacker forum, threatening to leak the data publicly if no buyer is found within a week.
TeamPCP released the Shai-Hulud supply-chain worm source code publicly and launched a $1K BreachForums bounty for new package compromises, dramatically lowering the barrier for copycat attacks.
UK AI Safety Institute re-tests a newer Mythos Preview checkpoint: it solves two cyber ranges including one previously unsolved, and updates its doubling-rate estimate to 4.7 months for AI cyber capability growth.
A critical elevation of privilege vulnerability (CVSS 8.6) in Azure AI Foundry M365 published agents could allow unauthorized remote attackers to escalate privileges over a network.
Google Threat Intelligence Group finds the first confirmed evidence of a criminal group using AI to develop a zero-day exploit for mass exploitation.
Microsoft Defender for Cloud signals reveal 15% of remote MCP servers allow unauthenticated access, and default Kubernetes deployments of Mage AI expose admin UIs to the internet.
Three malicious versions of the widely-used node-ipc npm package harvest 90 categories of developer and cloud credentials — including Claude AI and Kiro IDE settings — and exfiltrate via DNS TXT records to a fake Azure domain.
OpenAI confirms two employee devices were compromised in the Mini Shai-Hulud TanStack supply-chain attack, forcing rotation of macOS code-signing certificates for ChatGPT, Codex, and Atlas apps.
VulnCheck data shows massive year-over-year CVE increases across Chrome (+563%), GitHub (+476%), Mozilla (+157%), and Apache (+170%) — consistent with widespread adoption of AI models for vulnerability discovery.