GitHub Advisory — vLLM trust_remote_code bypass RCE
vLLM config loading can instantiate remote classes via auto_map even when trust_remote_code is false, enabling RCE; fixed by tightening the config path.
High-signal AI/security/automation notes.
vLLM config loading can instantiate remote classes via auto_map even when trust_remote_code is false, enabling RCE; fixed by tightening the config path.
AgentAudit reports 118 findings across 194 MCP/agent packages, with critical issues tied to unsanitized shell execution and secret leakage.
MUZZLE is an adaptive framework that discovers indirect prompt injection attacks against web agents by using their trajectories to craft malicious instructions.
New arXiv research compares MCP, A2A, Agora, and ANP protocol risks and proposes a protocol-level threat modeling framework.
A vLLM memory corruption bug in the Completions API prompt-embedding path can lead to DoS and potentially RCE; fixed in 0.11.1.
CVE-2026-1721: reflected XSS in Cloudflare Agents AI Playground OAuth callback could expose LLM chat history and connected MCP servers; fixed in agents-sdk 0.3.10.
Microsoft documents AI recommendation poisoning, where hidden prompt URLs attempt to write biased vendor preferences into assistant memory.
A new SoK surveys prompt injection attacks and defenses for LLM agents, introduces the AgentPI benchmark for context-dependent tasks, and reports that existing defenses struggle to balance trustworthiness, utility, and latency.
Microsoft researchers show a single unlabeled fine-tuning prompt can degrade safety alignment across multiple LLMs and diffusion models.
Praetorian releases Augustus, a Go-based open-source scanner for prompt injection, jailbreaks, and data extraction across LLM providers.
Moltbook’s agent network shows how hidden prompt injections can propagate like worms, with real samples already observed in the wild.
Trend Micro maps OpenClaw vs. ChatGPT Agent and highlights prompt injection, data exfiltration, and supply-chain risks in agentic assistants.
CVE-Factory converts sparse CVE metadata into executable agent tasks, enabling a continuously updated LiveCVEBench and large-scale training environments for agentic code-security systems.
Operant AI launches Agent Protector, a runtime security platform for discovering and governing autonomous AI agents across cloud, SaaS, and MCP toolchains.
Radware announces Agentic AI Protection, a runtime security layer to detect prompt injection, tool abuse, and unauthorized data access in autonomous AI agents.
CVE-2026-25546: command injection in godot-mcp (Model Context Protocol server) allows remote code execution via unsanitized projectPath; fixed in 0.1.1.
Agent-as-a-Proxy attacks bypass monitoring defenses by using agents as delivery mechanisms that evade both the agent and its monitor.
AutoInject uses reinforcement learning to generate transferable adversarial suffixes that boost prompt-injection success while preserving benign utility.