High-signal AI/security/automation notes.
Cisco open-sources the Foundry Security Spec, a structured specification for securing AI agents, MCP servers, and skills with YARA, LLM-based, and behavioral analysis scanners across AWS, Azure, and GCP deployments.
CERT/CC VU#221883 covers four CrewAI vulnerabilities that chain from prompt injection through sandbox escape, SSRF, and credential theft to full cloud account compromise.
Security researcher Tomer Peled discloses three vulnerabilities in MCP servers for Apache Doris, Apache Pinot, and Alibaba RDS — with Alibaba declining to patch.
Palo Alto Networks reports that frontier AI models (Mythos, Opus 4.7, GPT-5.5-Cyber) produced the majority of vulnerability findings across 130+ products, yielding 26 CVEs vs. the usual <5 per month.
Twelve sandbox escape vulnerabilities in the vm2 Node.js library (CVE-2026-24118 through CVE-2026-44009) threaten AI coding agents and code interpreters that rely on JS isolation.
A May 2026 study finds 37–56% of agent-generated Python code pins library versions with known critical CVEs — a systemic bias rooted in training data co-occurrence, not model-specific behavior.
The kanban npm package shipped with Cline CLI exposes three unauthenticated WebSocket endpoints on localhost; any website can hijack agent terminals and execute arbitrary commands.
DeepChat, an open-source AI agent platform, ships with two critical vulnerabilities: an Electron pop-up bypass enabling RCE via malicious Markdown links (CVSS 9.6) and a stored XSS vulnerability.
Forcepoint researchers found 10 live indirect prompt injection payloads targeting AI agents, including financial fraud, API key theft, recursive file deletion, and attribution hijacking.
Microsoft patched three critical information disclosure vulnerabilities in M365 Copilot and Copilot Chat in Edge, all leveraging improper neutralization of special elements in AI output.
A researcher demonstrated prompt injection attacks that hijacked AI agents from Anthropic, Google, and Microsoft via GitHub Actions — all three companies paid bounties quietly but published no advisories or CVEs.
The Mini Shai-Hulud supply-chain worm has escalated to 169 npm packages and 373 malicious versions across @tanstack, @mistralai, @uipath, and now PyPI, with autonomous self-propagation via stolen OIDC tokens.