arXiv — BadSkill: Agent Supply Chain Backdoor Attacks via Model-in-Skill Poisoning
New research reveals BadSkill attack where malicious agent skills bundle poisoned models that activate hidden payloads only when specific semantic triggers are met.
High-signal AI/security/automation notes.
New research reveals BadSkill attack where malicious agent skills bundle poisoned models that activate hidden payloads only when specific semantic triggers are met.
New arXiv paper introduces Meerkat, a clustering-based system that automatically detects rare safety violations, benchmark cheating, and reward hacking across thousands of AI agent execution traces.
New research introduces Semantic Intent Fragmentation (SIF) attack that bypasses LLM safety mechanisms by decomposing malicious requests into individually benign subtasks.
CVE-2026-5058 exposes critical pre-auth command injection in aws-mcp-server allowing arbitrary code execution on AI agent infrastructure connecting to AWS services.
CVE-2026-5556 allows remote code injection in badlogic pi-mono coding agent via extension loader, demonstrating supply chain risks in AI development tooling ecosystems.
Cloud Security Alliance briefing warns of AI agents being weaponized as command-and-control platforms via prompt injection, while AI-generated code floods production with systematic vulnerabilities.
Aonan Guan demonstrates Comment and Control, a cross-vendor prompt injection class that hijacks AI coding agents on GitHub Actions via PR titles and issue comments to steal repository secrets and API keys.
Depthfirst secured $80M Series B funding to expand its AI-native security platform, training specialized models for enterprise cybersecurity and accelerating autonomous vulnerability discovery.
Comprehensive guide to implementing input validation, output filtering, and behavioral guardrails for LangChain AI agents to prevent prompt injection and policy violations.
CVE-2026-30617 is a CVSS 8.6 RCE in LangChain-ChatChat 0.3.1 allowing unauthenticated remote attackers to execute arbitrary commands via MCP STDIO server configuration.
Langflow CVE-2026-33309 enables attackers to compromise AI workflow application logic and underlying infrastructure, posing critical risks to AI agent deployment environments.
Lyptus Research study finds AI offensive cyber capabilities doubling every 5.7 months, with Opus 4.6 and GPT-5.3 Codex achieving 50% success rates on complex security tasks.
Critical pre-authentication remote code execution vulnerability in Marimo Python notebook framework allows attackers to gain full shell access without authentication.
CVE-2026-33032 exposes an unauthenticated MCP endpoint in nginx-ui (CVSS 9.8), enabling full nginx server takeover. Actively exploited in the wild with public PoC.
Oasis Security details Claudy Day, a chain of Claude.ai vulnerabilities enabling invisible prompt injection via URL parameters, conversation history exfiltration via Files API, and Google Ads targeting.