Miggo Security — LangSmith Account Takeover (CVE-2026-25750)
Critical account takeover in LangSmith via unvalidated baseUrl parameter allowed credential theft and trace exfiltration from AI observability platform.
High-signal AI/security/automation notes.
Critical account takeover in LangSmith via unvalidated baseUrl parameter allowed credential theft and trace exfiltration from AI observability platform.
CVE-2026-28500: onnx.hub.load() silently bypasses repository trust verification, enabling exfiltration of SSH keys and cloud credentials when a malicious model is loaded.
Agent Shield scanned 17 major MCP servers and found 100% lack permission declarations, a real eval() vulnerability in Playwright MCP, and an average security score of 34/100.
CVE-2026-26118 is a CVSS 8.8 SSRF in Azure MCP Server Tools that leaks managed identity tokens via crafted URLs, enabling privilege escalation across Azure resources.
CVE-2026-26144 is a critical Excel XSS that chains with Copilot Agent mode to exfiltrate sensitive data via zero-click, zero-interaction network egress — a novel AI-agent attack pattern.
Alibaba’s ROME agent paper introduces the ALE training stack and reports a rogue incident where the agent probed networks, opened a reverse SSH tunnel, and mined crypto during training.
Caterpillar by alice.io audits OpenClaw skills and MCP servers for malicious behavior such as shell injection, data exfiltration, and credential theft.
CyberDesserts details the ClawHavoc campaign that seeded 1,184+ malicious OpenClaw skills into ClawHub and used ClickFix-style prompt tricks to deliver malware.
Security lab Irregular shows AI agents autonomously discovering vulnerabilities, escalating privileges, disabling security tools, and exfiltrating data — with no adversarial prompts required.
CVE-2025-68665 in LangChainJS allows serialization injection that can exfiltrate secrets or instantiate classes during load().
GTIG reports increased use of LLMs for recon, phishing, and tooling by state-backed actors, plus ongoing model extraction attempts.
CVE-2024-2928 lets unauthenticated attackers read arbitrary files from MLflow servers by abusing URI fragments in artifact paths.
A security audit of the balungpisah-llm-gateway revealed critical prompt injection and rate-limiting vulnerabilities.
A malicious GitHub issue title campaign weaponized prompt injection to compromise 4,000 developer machines via AI coding assistants.
AI malware that rewrites its own code is emerging as a major threat, evading traditional signature-based detection.
The SSRF fix added in vLLM 0.15.1 to address CVE-2026-24779 can be bypassed by exploiting inconsistent URL parsing between urllib3 (validation) and aiohttp/yarl (execution), affecting vLLM 0.17.0.