arXiv — LLM-agent threat model and attack taxonomy survey
A survey of LLM agent ecosystem threats that unifies input-level prompt attacks with protocol-level exploits and maps real incidents to a single threat model.
High-signal AI/security/automation notes.
A survey of LLM agent ecosystem threats that unifies input-level prompt attacks with protocol-level exploits and maps real incidents to a single threat model.
Check Point details Claude Code project configuration flaws enabling hook/MCP command execution and API key exfiltration when opening untrusted repos.
CrowdStrike’s 2026 Global Threat Report highlights prompt-injection abuse of GenAI tools, LLM-enabled malware, and faster breakout times.
Trail of Bits details how prompt injection against Perplexity’s Comet browser could exfiltrate Gmail data via agentic browsing tools.
AgentDyn is a new benchmark for indirect prompt injection in real-world agent workflows, with dynamic tasks and hundreds of test cases across common tool domains.
Pillar Security details Operation Bizarre Bazaar, a coordinated LLMjacking campaign targeting exposed LLM and MCP endpoints with commercial resale.
Socket details a Shai-Hulud-style npm worm that spreads via typosquats, hijacks CI workflows, and injects malicious MCP servers into AI coding tools.
Veza introduced Access Agents and expanded AI Agent Security to map and govern AI agent identities, tools, and permissions across MCP-connected environments.
A new arXiv study measures how prompt injections inside candidate documents can hijack LLM ranking pipelines and which model architectures resist them.
A compromised npm publish token led to an unauthorized Cline CLI release that added a postinstall script, highlighting supply-chain risk in agent tooling.
CVE-2025-54135: Cursor Agent could be coerced via prompt injection to create MCP config dotfiles and register a malicious server, enabling RCE; fixed in 1.3.9.
CVE-2026-2008: fermat-mcp eqn_chart uses eval on attacker-controlled equations, enabling code injection; no fixed version listed.
CVE-2025-53818: GitHub Kanban MCP Server uses exec() with user-controlled arguments, enabling command injection via tool calls; no patch listed.
CVE-2026-26029: command injection in sf-mcp-server (Salesforce MCP server for Claude Desktop) allows arbitrary shell command execution via query_records inputs; fixed by switching to execFile.
Kai Security AI reports on a honeypot MCP server and what 135 real AI-agent tool calls looked like, including credential-probing attempts.
Phoenix Security reports SANDWORM_MODE, a Shai-Hulud-style npm worm that steals secrets, poisons CI, and injects rogue MCP servers into AI coding assistants.
Unit 42’s 2026 IR report highlights AI as a force multiplier that compresses the attack lifecycle and increases speed-to-exfiltration.
CVE-2026-27203 lets attackers inject arbitrary environment variables in the ebay-mcp server by abusing token updates in its MCP toolchain.
Microsoft confirmed a Microsoft 365 Copilot Chat bug that summarized confidential emails despite sensitivity labels and DLP policies.