High-signal AI/security/automation notes.
A cross-site scripting flaw in Excel executes on file open and chains to Copilot Agent, enabling silent exfiltration of spreadsheet data to attacker-controlled endpoints.
OX Security publishes full vulnerability advisory for MCP STDIO command injection with CVEs assigned across LangFlow, LiteLLM (CVE-2026-30623), Agent Zero (CVE-2026-30624), GPT Researcher (CVE-2025-65720), Fay, and LangBot.
vLLM patches a critical RCE in protobuf.js that allows arbitrary JavaScript code execution via malicious schema definitions, affecting the dominant open-source LLM inference framework.
Wiz Research traces a six-wave GitHub Actions supply chain campaign using AI-generated payloads across 500+ malicious PRs exploiting pull_request_target misconfigurations, compromising npm packages and stealing cloud credentials.
Research auditing 428 LLM API routers found 9 injecting malicious tool calls, 17 harvesting credentials, and one actively draining crypto wallets — a new AI supply-chain threat vector.
FastGPT, an open-source AI agent building platform, ships with critical NoSQL injection flaws that allow unauthenticated admin login and authenticated account takeover.
GreyNoise honeypots captured 91,403 attack sessions against exposed LLM endpoints between October 2025 and January 2026, revealing systematic reconnaissance and exploitation of misconfigured AI deployments.
Hadrian catalogs 70 open-source AI pentesting tools as of March 2026, with agents achieving IP-to-shell for under $1 and 156x cost reduction versus human-led engagements.
Audit of 428 LLM API routers finds active payload injection in 9 services, credential harvesting in 17, and confirmed crypto wallet draining — exposing a hidden supply-chain risk for AI agent deployments.
CVE-2026-35402 in mcp-neo4j-cypher lets LLM agents bypass read-only restrictions using CALL stored procedures, enabling data modification and SSRF.
VentureBeat survey finds most enterprises observe but cannot enforce or isolate AI agent behavior, while 97% of security leaders expect a major agent-driven incident within a year.
Cisco open-sources a comprehensive AI agent security toolkit including DefenseClaw, MCP Scanner, Skill Scanner, A2A Scanner, and AI BOM — addressing the full agentic AI threat surface.
A single threat actor leveraged Claude Code and GPT-4.1 to compromise nine Mexican government agencies, stealing 195M citizen records in a campaign that ran from December 2025 to February 2026.
Abnormal Security discovers ATHR, a commercial cybercrime platform that uses AI voice agents to automate the entire telephone-oriented attack delivery (TOAD) chain — from email lures to credential harvesting for Google, Microsoft, and Coinbase.
Cisco Talos reports a 686% increase in phishing emails abusing n8n AI workflow automation webhooks to deliver malware and fingerprint devices via trusted cloud domains.
Cloudflare publishes its internal MCP security architecture covering authorization controls, prompt injection defense, supply chain governance, and Shadow MCP detection for enterprise AI agent deployments.
Google Cloud/Mandiant warn that AI models are compressing the zero-day attack timeline, enabling mass exploitation campaigns, and call for AI-integrated defensive roadmaps to counter machine-speed threats.
RSAC 2026 researchers achieved 76% prompt injection success rate against Apple Intelligence using Neural Exec and Unicode bidirectional tricks, patched in iOS 26.4 / macOS 26.4.
Microsoft documents an AI-driven phishing campaign using dynamic code generation, generative AI lures, and serverless infrastructure to bypass MFA and compromise organizational accounts.