Posts
High-signal AI/security/automation notes.
Anthropic Officially Launches Project Glasswing — $100M Commitment, 12 Partners, Thousands of Zero-Days Found
Anthropic officially announces Project Glasswing with AWS, Apple, Microsoft, Google and 8 other partners, committing $100M in Mythos Preview credits after the model autonomously discovered thousands of zero-day vulnerabilities across major OSes and browsers.
“Comment and Control” — Prompt Injection Hijacks Claude Code, Gemini CLI & Copilot via GitHub
A new cross-vendor prompt injection class weaponizes GitHub PR titles, issue bodies and comments to hijack AI coding agents and steal CI/CD credentials — affecting Claude Code, Gemini CLI and GitHub Copilot Agent.
Comment and Control — Prompt Injection Leaks Secrets in Three AI Coding Agents
A single prompt injection in a GitHub PR title caused Claude Code, Gemini CLI, and GitHub Copilot Agent to leak their own credentials — rated CVSS 9.4 Critical by Anthropic.
Forcepoint X-Labs Finds 10 Indirect Prompt Injection Payloads on Live Websites
Forcepoint X-Labs telemetry detected 10 verified indirect prompt injection payloads actively deployed on public websites — targeting API key theft, data destruction and financial fraud via AI agents.
LiteLLM PyPI Compromised — Multi-Stage Credential Stealer in 3M-Download Package
Malicious versions of the widely used litellm package were published to PyPI, deploying a three-layer credential stealer that harvested cloud keys, SSH credentials, Kubernetes tokens, and crypto wallets.
Lovable — BOLA Exposes AI Chat Histories and Database Credentials in Vibe Coding Platform
npm CanisterWorm — Self-Spreading Supply-Chain Attack Targets AI Agent Tooling
A self-propagating supply-chain worm infected multiple npm packages from Namastex Lab, stealing credentials and recursively spreading to other packages the attacker can publish.
NVIDIA — Indirect AGENTS.md Injection in OpenAI Codex via Malicious Dependencies
NVIDIA AI Red Team demonstrates how a malicious Go dependency can overwrite AGENTS.md to hijack OpenAI Codex, inject stealth code changes, and suppress PR summaries.
Red Hat RHEL AI — Two InstructLab CVEs: Path Traversal & trust_remote_code RCE
Red Hat RHEL AI ships with two newly disclosed CVEs in InstructLab — a path traversal in the chat session handler and a hardcoded trust_remote_code that enables arbitrary code execution from HuggingFace models.
Anthropic MCP Design Flaw Enables RCE Across the AI Ecosystem
Anthropic — Unauthorized Access to Mythos AI Model
Anthropic confirms it is investigating unauthorized access to its unreleased Mythos model, obtained via a third-party contractor environment, raising concerns about how dangerous AI capabilities are kept under control.
Apache ActiveMQ CVE-2026-34197 — Claude Discovers 13-Year-Old RCE in 10 Minutes
Brex — CrabTrap Open-Source LLM-as-a-Judge Proxy for AI Agent Security
Brex released CrabTrap, an open-source HTTP proxy that intercepts every outbound request from AI agents and evaluates it against security policies using a combination of static rules and LLM judgment.
CSA Survey — 82% of Enterprises Have Unknown AI Agents in Their Environments
A Cloud Security Alliance survey reveals that 82% of enterprises have undiscovered AI agents running in their infrastructure, with 65% experiencing agent-related incidents in the past year.
CVE-2026-26144: Excel XSS Chains to Copilot Agent for Silent Data Exfiltration
Mondoo — Free AI Agent Skills Security Checker Launches
Mondoo launches AI Skills Check, a free agent-agnostic security scanner for AI agent skills across ClawHub and Skills.sh registries, after researchers found 1,184 malicious skills on ClawHub alone.
MCPwn: Actively Exploited nginx-ui Auth Bypass (CVE-2026-33032)
Pillar Security — Google Antigravity Sandbox Escape via Prompt Injection
CERT — CVE-2026-5752 Terrarium Sandbox Escape via Pyodide Prototype Chain Traversal
CVE-2026-5752 is a 9.3-rated sandbox escape in Terrarium that allows arbitrary code execution with root privileges via JavaScript prototype chain traversal in the Pyodide WASM environment.