Posts
High-signal AI/security/automation notes.
Pentera — Claude Desktop Turned Into Double Agent via Personalization Sync
TOCTOU Attack Tricks AI Computer-Use Agents Into Clicking the Wrong Thing
Anthropic — Buffa Rust Library 0-Day: 22x Heap Amplification via Protobuf Unknown Fields
CVE-2026-50143 — Apify MCP Server Token Leak via Path Authority Injection
High-severity flaw in @apify/actors-mcp-server lets attackers inject malicious paths that leak Apify tokens to unauthorized parties.
arXiv — Lifecycle & Application-Stack Survey of LLM Vulnerabilities (WPI SoK)
WPI researchers publish the first lifecycle and application-stack SoK of LLM vulnerabilities, mapping attacks across eight stages from data collection to agent execution.
Cursor — DuneSlide: Two Zero-Click RCEs Let Prompt Injection Escape the Sandbox
Cato AI Labs discloses DuneSlide, two CVSS 9.8 flaws in Cursor IDE that let prompt injection overwrite the sandbox binary and achieve zero-click RCE.
Sysdig JADEPUFFER — First Documented Agentic Ransomware Operation
Sysdig documents JADEPUFFER, an LLM agent that ran a full ransomware campaign from Langflow RCE to production database extortion — autonomously.
Socket — AI Coding Agents Are the Supply Chain Blind Spot Nobody Mapped
AI agents pull packages past scanners, enabling PromptMink, slopsquatting, and Clinejection attacks that bypass human review entirely.
Adversa AI — GuardFall: Decades-Old Bash Tricks Bypass Shell Guards in 10 of 11 AI Coding Agents
Adversa AI discovers GuardFall, a class of shell injection bypasses where decades-old Bash quoting tricks defeat pattern-based guards in popular open-source AI coding agents.
Anthropic — Claude Fable 5 Returns With Industry Jailbreak Framework After Export Controls Lifted
Anthropic redeploys Fable 5 globally after export controls lifted, alongside a new cross-industry jailbreak severity framework developed with Amazon, Microsoft, and Google.
Apple — Accelerated Security Updates in Response to AI-Powered Threats
Apple pulled 29 WebKit security fixes forward from the iOS 26.6 cycle, citing AI-driven attack speed as the reason for breaking its traditional patch cadence.
LayerX — BioShocking: AI Browser Guardrail Bypass via Fictional Context Manipulation
LayerX researchers demonstrate BioShocking, a prompt injection technique that tricks six AI browsers into abandoning safety guardrails by establishing a fictional context — affecting ChatGPT Atlas, Comet, Fellou, Genspark, Sigma, and Claude Chrome.
Adversa AI — GuardFall: Bash Tricks Bypass Safeguards in 10 of 11 AI Coding Agents
Adversa AI reveals GuardFall, a structural flaw where decades-old Bash shell tricks bypass pattern-based guards in open-source AI coding agents, turning malicious repos into supply chain attack vectors.
Sysdig — First Exploitation of Langflow CVE-2026-55255 IDOR Chained with RCE
Microsoft — Poisoned MCP Tool Descriptions Make AI Agents Silently Exfiltrate Company Data
Microsoft research demonstrates how attackers can hijack enterprise AI agents through poisoned MCP tool descriptions, triggering silent data exfiltration without breaking any access rules.
Unit 42 — Phantom Squatting: Attackers Weaponize AI-Hallucinated Domains for Phishing and Malware
Unit 42 found 250,000 unregistered domains hallucinated by LLMs — adversaries are pre-registering them to intercept AI-agent traffic.
Cursor CVE-2026-26268 — Sandbox Escape Lets Attackers Achieve RCE via Prompt Injection in AI Coding Agent
Critical sandbox escape in Cursor AI editor chains prompt injection through MCP manipulation to achieve arbitrary code execution on developer machines.
Djinn Stealer — SimpleHelp CVE-2026-48558 Exploit Targets MCP Configs and AI Dev Credentials
New Djinn Stealer deployed via SimpleHelp RMM exploit specifically harvests MCP configs, AI coding assistant tokens, and cloud credentials from developer machines.
MCP Protocol Rewrite — Session IDs Removed, Security Decisions Shifted to Developers
The biggest MCP rewrite since launch removes session IDs to fix session hijacking but shifts authentication and authorization decisions to server implementers.