LWN — GitHub issue title prompt injection compromises 4,000 developer machines
A malicious GitHub issue title campaign weaponized prompt injection to compromise 4,000 developer machines via AI coding assistants.
High-signal AI/security/automation notes.
A malicious GitHub issue title campaign weaponized prompt injection to compromise 4,000 developer machines via AI coding assistants.
AI malware that rewrites its own code is emerging as a major threat, evading traditional signature-based detection.
The SSRF fix added in vLLM 0.15.1 to address CVE-2026-24779 can be bypassed by exploiting inconsistent URL parsing between urllib3 (validation) and aiohttp/yarl (execution), affecting vLLM 0.17.0.
A new paper proposes a context-aware privacy instructor model for LLM agents that improves privacy-helpfulness tradeoffs under adversarial conditions.
A new paper shows how visually embedded adversarial instructions in images can hijack multimodal LLM behavior in black-box settings.
GitHub warns that Copilot CLI’s shell tool misclassifies dangerous bash parameter expansions as read-only, enabling command execution (CVE-2026-29783).
Huntress reports malicious GitHub repos posing as OpenClaw installers that delivered info stealers and GhostSocks proxies via search-result poisoning.
CVE-2026-29787 exposes system details via mcp-memory-service’s /api/health/detailed endpoint when anonymous access is enabled.
Noma Security disclosed ContextCrush: a supply-chain prompt injection path in Context7’s MCP server custom rules that can steer IDE agents to execute attacker instructions.
CVE-2026-29791: Agentgateway’s MCP-to-OpenAPI proxy fails to sanitize path, query, and header inputs, enabling parameter injection.
A practical threat model for AI agents: assets, trust boundaries, common attack paths, and controls that actually work in production.
Check Point details Claude Code project-file weaknesses that enabled RCE and API key exfiltration via hooks, MCP servers, and env vars in untrusted repos.
How to secure the tool ecosystem: MCP servers, agent skills, plugins, and the software supply chain behind them.
Microsoft Defender reports malicious AI-themed browser extensions harvesting LLM chat histories and browsing telemetry, exposing sensitive enterprise data.
A practical defense playbook: detection, mitigation, and red‑team TTPs for prompt injection across agents and tool ecosystems.
Cisco Talos’ 2025 CVE retrospective introduces AI keyword tracking and reports AI-related CVEs nearly doubled YoY to 330, with MCP and Claude appearing for the first time.
VulnerableMCP aggregates MCP server and agent tooling vulnerabilities with impact, exploitability, and source links for defenders.
CVE-2026-27825 allows unauthenticated file writes via mcp-atlassian attachment tools, enabling RCE; CVE-2026-27826 adds header-driven SSRF.
CVE-2026-3484 exposes command injection in nmap-mcp-server via child_process.exec, risking arbitrary command execution in MCP toolchains.