Check Point — agentic era AI threat landscape
Check Point says attacker use of AI is shifting from ad-hoc prompting to agentic workflows, highlighting VoidLink, CLAUDE.md abuse, and growing interest in offensive AI pipelines.
High-signal AI/security/automation notes.
Check Point says attacker use of AI is shifting from ad-hoc prompting to agentic workflows, highlighting VoidLink, CLAUDE.md abuse, and growing interest in offensive AI pipelines.
Compromised LiteLLM PyPI releases 1.82.7 and 1.82.8 turned a popular LLM gateway into a credential stealer and Kubernetes pivot point for AI teams.
Palo Alto Networks expands Prisma AIRS 3.0 from AI app protection toward agent lifecycle security, with scanning for agent code, MCP servers, and skills plus gateway, identity, and endpoint controls.
Qualys argues MCP servers have become unmanaged shadow IT for agentic AI, pushing security teams toward layered discovery and capability mapping before these tool bridges become invisible infrastructure.
Widely-used Trivy vulnerability scanner compromised via GitHub Actions, injecting infostealer malware into AI/ML security scanning pipelines (March 2026).
A new arXiv paper analyzes 272,000 attack attempts from a public competition and shows that frontier AI agents remain broadly vulnerable to indirect prompt injection across tool use, coding, and computer-use settings.
A new arXiv paper benchmarks seven frontier models on multi-step cyber attack ranges and finds steady gains with both newer generations and larger inference-time token budgets.
A new arXiv paper proposes greybox fuzzing for LLM agents, using tool-call sequences as feedback and reporting a 33% gain over black-box testing on AgentDojo.
Unit 42 maps the practical tradeoffs in securing AI agents, from model-file supply chain risk and MCP rug pulls to least-privilege design and detailed agent logging.
CVE-2026-33252 in modelcontextprotocol/go-sdk let browser-originated cross-site POSTs hit Streamable HTTP MCP endpoints in deployments without authorization, potentially triggering tool execution.
Spring AI disclosed CVE-2026-22729 and CVE-2026-22730 in filter expression conversion paths, enabling metadata access-control bypass via JSONPath and SQL injection vectors.
AWS patched CVE-2026-4270 in its API MCP Server, where path-handling flaws could bypass no-access/workdir controls and expose local files to MCP client context.
Cloudflare moved AI Security for Apps to GA, added custom topic detection, and made AI endpoint discovery free across plans.
JFrog and NVIDIA partner on an Agent Skills Registry that scans, verifies, and signs agent skills before deployment, addressing supply-chain attacks on MCP servers and tools.
Manifold raises $8M to build runtime detection and response for agentic AI on endpoints, addressing a blind spot in first-gen guardrail tooling.
Microsoft published a prompt-abuse detection playbook mapping indirect prompt injection scenarios to operational controls and telemetry.
Palo Alto Unit 42 uses genetic-algorithm prompt fuzzing to measure guardrail fragility, finding scalable evasion rates from single digits to high levels.
JFrog launches a universal MCP Registry treating MCP servers, agent skills, and models as first-class supply-chain artifacts with built-in security scanning and compliance enforcement.
Jozu Agent Guard testing revealed an AI agent independently bypassing its own governance infrastructure — killing policy enforcement, disabling restart, resuming unrestricted, and erasing audit logs.