T3MP3ST — Open-Source Framework Turns AI Coding Agents Into Autonomous Red Teamers
T3MP3ST orchestrates Claude Code, Codex, and Hermes agents through a recon-to-exploit kill chain with no additional API keys or cloud infrastructure.
High-signal AI/security/automation notes.
T3MP3ST orchestrates Claude Code, Codex, and Hermes agents through a recon-to-exploit kill chain with no additional API keys or cloud infrastructure.
Critical CVSS 9.4 path traversal in fast-mcp-telegram lets remote attackers bypass session controls and authenticate as the default legacy user via crafted Bearer tokens.
ICML 2026 paper traces prompt injection to role confusion in LLMs and introduces CoT Forgery, a zero-shot attack achieving 60% success against frontier models.
Palo Alto Networks Unit 42 found five malicious OpenClaw skills on ClawHub that evaded VirusTotal and ClawScan, delivering macOS infostealers and running agentic financial fraud.
Alibaba plans to ban Claude Code across workplaces after a Reddit user alleged the tool covertly detected Chinese AI labs and modified its system prompt.
New research audits LangChain, LlamaIndex, and Stripe Agent Toolkit for per-call authorization — all three ship capability gating but none ships deterministic fail-closed authorization by default.
New research identifies 9 structural vulnerabilities in LLM agent memory systems and introduces MPBench, showing aggressive memory-writing agents are more exploitable and existing prompt injection defenses fail to cover memory poisoning.
First in-depth security analysis of offensive security agents reveals shared design flaws enabling API key exfiltration, persistent footholds, and operator machine compromise even inside sandboxes.
Black Hat 2026 briefing reveals a purpose-trained 30B open-source model achieves 56% exploit success rate against AI agents at 70-125x lower cost than frontier models.
Obsidian Security discloses critical Flowise flaw where importing a malicious workflow file triggers remote code execution via MCP stdio transport.
Threat actors exploit a CVSS 9.3 Langflow vulnerability to deploy custom Monero miners, turning exposed AI app endpoints into cryptojacking gateways.
LiteLLM PyPI package compromised — malicious versions 1.82.7 and 1.82.8 shipped a multi-stage credential stealer targeting cloud keys, CI/CD secrets, and crypto wallets.
High-severity flaw in @apify/actors-mcp-server lets attackers inject malicious paths that leak Apify tokens to unauthorized parties.