High-signal AI/security/automation notes.
Capsule Security disclosed CVE-2026-21520 (ShareLeak) in Microsoft Copilot Studio and PipeLeak in Salesforce Agentforce — indirect prompt injection via public forms leading to data exfiltration.
OpenAI discloses Axios npm supply chain attack affecting GitHub Actions workflow with access to macOS app signing certificates, highlighting critical AI infrastructure supply chain risks.
New arXiv research introduces MCP-DPT, a defense-placement taxonomy that maps 49 MCP-specific attacks to architectural layers and identifies critical security gaps in AI agent ecosystems.
GitHub Security Advisories disclose two critical MCP vulnerabilities: PraisonAI environment exposure and FrontMCP SSRF, highlighting systemic risks in AI agent toolchains.
Trend Micro researchers discovered sockpuppeting — a single-line code jailbreak that bypasses safety guardrails in 11 LLMs including ChatGPT, Claude, and Gemini with up to 15.7% success rate.
Two critical Chrome vulnerabilities (CVE-2026-5885 and CVE-2026-5874) in AI components expose memory data and enable sandbox escape attacks, highlighting security risks in browser-based machine learning.
LiteLLM versions through 2026-04-08 contain a critical remote code execution vulnerability via bytecode rewriting at /guardrails/test_custom_code endpoint.
parisneo/lollms contains a critical stored XSS vulnerability (CVSS 9.6) allowing authenticated attackers to inject persistent malicious scripts through social posting features.
CVE-2026-35568 exposes DNS rebinding vulnerability in MCP Java SDK allowing attackers to bypass origin validation and execute arbitrary tool calls on local MCP servers with CVSS 7.6 severity.
Microsoft Patch Tuesday addresses critical remote code execution vulnerabilities CVE-2026-26113 and CVE-2026-26110 affecting Office applications through Preview Pane exploitation.
Protocol-level vulnerabilities in AI trading agents led to over $45M in crypto losses, exposing memory poisoning risks and weak authentication in autonomous trading systems.
AI data startup Mercor confirms 4TB breach from LiteLLM supply chain attack, exposing Meta, OpenAI, and Anthropic training methodologies and triggering class action lawsuit.
Microsoft releases open-source Agent Governance Toolkit addressing all 10 OWASP Agentic AI Top 10 risks with sub-millisecond policy enforcement for autonomous AI agents.
Nicholas Carlini (Anthropic) used Claude to discover CVE-2026-33017 in FreeBSD RPCsec GSS and autonomously develop a complete remote kernel exploit with root shell access.