GitLost — GitHub Agentic Workflows Leak Private Repos via Prompt Injection
Noma Labs discovered GitLost, a critical indirect prompt injection in GitHub Agentic Workflows that lets unauthenticated attackers exfiltrate private repository content.
High-signal AI/security/automation notes.
Noma Labs discovered GitLost, a critical indirect prompt injection in GitHub Agentic Workflows that lets unauthenticated attackers exfiltrate private repository content.
CVE-2026-55646 lets unauthenticated API callers exhaust memory via oversized audio uploads; CVE-2026-55574 enables indefinite inference worker hangs via adversarial regex patterns.
vLLM speech-to-text endpoints allocate full upload before enforcing audio file-size limit, enabling remote memory exhaustion DoS. Fixed in 0.24.0.
Two campaigns use SEO poisoning and indirect prompt injection to manipulate AI agents into making cryptocurrency payments or trusting fraudulent DeFi platforms.
June 2026 set a record for high- and top-severity CVEs among 21 notable organizations, driven by AI-powered vulnerability discovery tools like Claude Mythos and GPT-5.5-Cyber.
runZero researchers used GitHub Copilot to fuzz FatFs, a compact C library for FAT/exFAT media parsing, discovering 7 CVEs affecting IoT devices, drones, ATMs, and voting machines.
Microsoft introduces Execution Containers (MXC), a new security layer for containing AI agent workflows on Windows with policy-driven isolation and identity enforcement.
NVIDIA open-sourced SkillSpector, a security scanner that detects vulnerabilities, malicious patterns, and supply-chain risks in AI agent skills before installation.
TrendAI analysis of 9,695 MCP servers found 4,982 security issues across 2,259 servers, debunking assumptions about popularity and verification badges.
CMU SEI launches FLARE-AI, an open-source platform that routes AI flaw reports to vendors, CERT/CC, and government agencies for coordinated disclosure.
The IMA attack framework achieves 89% jailbreak success against MetaGPT, CrewAI, and other multi-agent systems by exploiting collaboration dynamics that amplify harm over single-agent baselines.
Tencent Zhuque Lab releases AI-Infra-Guard, an open-source framework spanning infrastructure, protocol, agent, and model layers for comprehensive AI agent red teaming.
New research demonstrates that static skill scanners fail against adaptive evasion techniques, with SkillCloak bypassing over 90% of defenses while preserving malicious functionality.