High-signal AI/security/automation notes.
AI social media scheduling tool Postiz ships a stored XSS vulnerability (CVSS 8.9) allowing authenticated users to upload executable content via Content-Type header spoofing — fixed in v2.21.6.
The UK AI Safety Institute found all tested frontier LLMs remain highly vulnerable to basic jailbreaks, with several completing high-school-level cyber challenges.
Palo Alto Networks Unit 42 warns that frontier AI models can now function as full-spectrum security researchers, autonomously discovering zero-days and chaining exploit paths.
Dark web intelligence reveals underground operators are using Claude, Gemini and ChatGPT with better prompts — not ablated models like WormGPT — for exploit development and payload generation.
Vercel confirmed a security breach after a compromised Google Workspace OAuth app belonging to a third-party AI tool (Context.ai) gave attackers access to internal systems and customer environment variables.
Georgia Tech researchers track 74 confirmed CVEs directly caused by AI-assisted coding tools, with 35 disclosed in March 2026 alone — and estimate the real number is 5–10× higher.
arXiv:2604.11790 introduces ClawGuard, a runtime security framework that enforces deterministic rule-based controls at every tool-call boundary to block indirect prompt injection across web, MCP, and skill-file attack vectors.
GreyNoise honeypots captured 91,403 attack sessions targeting LLM infrastructure, including systematic enumeration of 73+ model endpoints and SSRF campaigns exploiting Ollama.
iProov Threat Intelligence Report 2026 documents a 1,151% surge in iOS-targeted injection attacks using fake video and biometric data to bypass identity verification systems, alongside a 720% spike in Southeast Asia.
arXiv:2603.28013 — MIT and University of Chicago researchers track prompt injection through four kill-chain stages across five frontier models, revealing that write-node placement is the highest-leverage safety decision in agent pipelines.
A cross-site scripting flaw in Excel executes on file open and chains to Copilot Agent, enabling silent exfiltration of spreadsheet data to attacker-controlled endpoints.
OX Security publishes full vulnerability advisory for MCP STDIO command injection with CVEs assigned across LangFlow, LiteLLM (CVE-2026-30623), Agent Zero (CVE-2026-30624), GPT Researcher (CVE-2025-65720), Fay, and LangBot.
vLLM patches a critical RCE in protobuf.js that allows arbitrary JavaScript code execution via malicious schema definitions, affecting the dominant open-source LLM inference framework.
Wiz Research traces a six-wave GitHub Actions supply chain campaign using AI-generated payloads across 500+ malicious PRs exploiting pull_request_target misconfigurations, compromising npm packages and stealing cloud credentials.
Research auditing 428 LLM API routers found 9 injecting malicious tool calls, 17 harvesting credentials, and one actively draining crypto wallets — a new AI supply-chain threat vector.