arXiv — Prompt Injection 2.0: hybrid AI threats
A new paper maps how prompt injection pairs with classic web exploits to create hybrid AI threats and proposes architectural mitigations.
High-signal AI/security/automation notes.
A new paper maps how prompt injection pairs with classic web exploits to create hybrid AI threats and proposes architectural mitigations.
BlacksmithAI is an open-source, multi-agent penetration testing framework that orchestrates recon through post-exploitation with configurable LLM backends.
CVE-2026-25536 in @modelcontextprotocol/sdk can leak tool responses across clients when a shared server/transport instance is reused.
CVE-2026-23744 enables remote code execution in MCPJam Inspector via an unauthenticated HTTP endpoint that can install MCP servers.
Oasis Security details ClawJacked, a localhost WebSocket attack chain that let any website hijack OpenClaw agents and brute-force gateway passwords, fixed in v2026.2.25+.
A new survey maps jailbreak attacks and defenses across LLMs and VLMs, proposing a unified, layered defense model.
ServiceNow patches CVE-2026-0542, an unauthenticated RCE in the ServiceNow AI Platform sandbox, with updates for hosted and self-hosted deployments.
A vLLM config path instantiates classes from auto_map without honoring trust_remote_code, enabling remote code execution when loading model configs.
CVE-2026-27896 in the MCP Go SDK breaks JSON-RPC field strictness via case-insensitive and Unicode-folded matching, enabling method/params confusion.
CVE-2026-27735 allows path traversal in mcp-server-git’s git_add tool, letting attackers stage files outside the repo boundary for potential exfiltration.
The 2025 AI Agent Index surveys 30 deployed agents and finds major gaps in safety disclosures, testing transparency, and accountability.
Orca Security details RoguePilot, a passive prompt injection in GitHub Codespaces that can coerce Copilot to exfiltrate GITHUB_TOKENs.
A new arXiv study benchmarks prompt-injection and jailbreak robustness across open-source LLMs and finds lightweight defenses are bypassable.
Endor Labs details six patched OpenClaw vulnerabilities (SSRF, auth bypass, path traversal) found via agentic data-flow analysis, with CVEs and GHSAs covering tool and webhook attack paths.
SD Times highlights MCP security and privacy gaps, including prompt injection risk, server verification challenges, and runtime policy enforcement needs.
A new arXiv paper maps agentic AI runtime supply-chain threats, from context injection to tool supply-chain abuse, and proposes zero-trust runtime defenses.
Silent Egress shows how URL preview prompt injection can trigger stealthy data exfiltration in tool-using LLM agents, and why network egress controls matter.
IBM’s 2026 X-Force Threat Intelligence Index flags AI-accelerated attacks, dark‑web trading of AI chatbot credentials, and a surge in exploitation of public‑facing apps.
IronCurtain proposes MCP-proxy sandboxing with policy enforcement and isolated execution modes for personal AI agents.
Researchers propose a circuit-level jailbreak method (HMNS) that suppresses attention heads and injects nullspace perturbations to bypass safety defenses with fewer queries.