High-signal AI/security/automation notes.
Microsoft disclosed CVE-2026-32211, a critical authentication bypass vulnerability in Azure MCP Server that allows unauthorized access to sensitive data with CVSS 9.1 severity.
New research reveals BadSkill attack where malicious agent skills bundle poisoned models that activate hidden payloads only when specific semantic triggers are met.
New arXiv paper introduces Meerkat, a clustering-based system that automatically detects rare safety violations, benchmark cheating, and reward hacking across thousands of AI agent execution traces.
New research introduces Semantic Intent Fragmentation (SIF) attack that bypasses LLM safety mechanisms by decomposing malicious requests into individually benign subtasks.
CVE-2026-5058 exposes critical pre-auth command injection in aws-mcp-server allowing arbitrary code execution on AI agent infrastructure connecting to AWS services.
CVE-2026-5556 allows remote code injection in badlogic pi-mono coding agent via extension loader, demonstrating supply chain risks in AI development tooling ecosystems.
Cloud Security Alliance briefing warns of AI agents being weaponized as command-and-control platforms via prompt injection, while AI-generated code floods production with systematic vulnerabilities.
Aonan Guan demonstrates Comment and Control, a cross-vendor prompt injection class that hijacks AI coding agents on GitHub Actions via PR titles and issue comments to steal repository secrets and API keys.
Depthfirst secured $80M Series B funding to expand its AI-native security platform, training specialized models for enterprise cybersecurity and accelerating autonomous vulnerability discovery.
Comprehensive guide to implementing input validation, output filtering, and behavioral guardrails for LangChain AI agents to prevent prompt injection and policy violations.
CVE-2026-30617 is a CVSS 8.6 RCE in LangChain-ChatChat 0.3.1 allowing unauthenticated remote attackers to execute arbitrary commands via MCP STDIO server configuration.