AWS MCP Gateway Registry SQL Injection Exposes API Key Material — CVE-2026-14471
AWS patched CVE-2026-14471, a high-severity authenticated SQL injection in MCP Gateway Registry versions 1.0.3 through 1.0.12 that can expose API key material.
High-signal AI/security/automation notes.
AWS patched CVE-2026-14471, a high-severity authenticated SQL injection in MCP Gateway Registry versions 1.0.3 through 1.0.12 that can expose API key material.
Google has put Cloud Run sandboxes into public preview, adding credential isolation, default-deny network egress, and disposable filesystem overlays for AI-generated code.
Tongji researchers propose SpellSmith, a text-based mitigation that embeds behavioral guardrails into MCP tool descriptions to block taint-style exploits without code-level patches.
Three high-severity vulnerabilities in OpenClaw let attackers chain environment variable injection, git transport abuse, and Docker sandbox escape to achieve host-level code execution via WhatsApp messages.
Tel Aviv University researchers demonstrate how attackers can weaponize LLM hallucinations to establish agentic botnets, achieving 100% attack success against multiple AI coding assistants.
CrowdStrike expands its prompt injection taxonomy to over 200 techniques, revealing how attacks against AI agents are fragmenting into composite chains.
Palo Alto Networks Unit 42 disclosed a critical vulnerability in Google Cloud Vertex AI SDK that allowed cross-tenant model poisoning and remote code execution via bucket squatting.
CISA adds Langflow CVE-2026-55255 to its Known Exploited Vulnerabilities catalog — the first AI agent orchestration platform ever listed — with a July 10 deadline.
New research demonstrates workflow-level jailbreak construction: coding agents that refuse harmful prompts in chat will produce the same harmful content when asked to write it as code.
The EU published an Action Plan on July 7, 2026 to address risks and opportunities of advanced AI for cybersecurity, including AI model evaluation, structured access, and secure testing platforms.
Fiddler AI maps the full coding-agent attack surface — prompt injection, supply-chain poisoning, credential leaks, MCP spoofing — and proposes runtime guardrails.
Sygnia reports a single threat actor used agentic AI workflows to execute a full cloud compromise in 72 hours — a campaign that would have taken weeks manually.
TeamPCP poisoned Trivy, Checkmarx KICS, LiteLLM, and Telnyx SDK to harvest 500K+ CI/CD credentials — VECT ransomware then selected victims from the archive.
Seoul National University and UIUC researchers introduce Agent Data Injection, a new class of indirect prompt injection that exploits lack of trusted/untrusted data isolation in LLM agents.
LocalAI before the latest patch contains an unauthenticated SSRF vulnerability in POST /models/apply that allows attackers to fetch arbitrary internal URLs.