Posts
High-signal AI/security/automation notes.
PromptSnatcher — Chrome Ad-Blockers Secretly Intercepting AI Chats
Two Chrome ad-blocker extensions with 100K+ users have been caught silently exfiltrating full conversation histories from ChatGPT, Claude, Gemini, and five other AI platforms.
Rapid7 — Modernizing Vulnerability Standards for the AI Era
Rapid7 presented a White House policy paper arguing that CVE, CVSS, NVD, and KEV infrastructure were built for human-speed discovery and cannot keep pace with AI-driven vulnerability research.
Wake Forest — 282 iOS AI Apps Leak LLM API Keys in Network Traffic
Wake Forest study finds 282 of 444 iOS AI apps expose API keys or open relays in plaintext network traffic, enabling LLMjacking and unauthorized inference theft.
CVE-2026-33017 — Langflow RCE Exploited for Monero Mining on AI Servers
CVE-2026-33017 (CVSS 9.3) in Langflow allows unauthenticated RCE via Python code injection, actively exploited to deploy Monero cryptominers on AI infrastructure.
CVE-2026-40933 — Flowise MCP stdio RCE: 1-Click Server Takeover via Malicious Workflow
Forbes — Gartner Tells CISOs to Block All AI Browsers as Prompt Injection Defenses Fail
Gartner advises blocking ChatGPT Atlas and Perplexity Comet as CrowdStrike reports prompt injection at 90+ organizations and AI-enabled attacks surge 89%.
Miasma — LeoPlatform Supply Chain Attack Expands to Go, Targets AI Coding Assistants
Miasma malware compromises 23 LeoPlatform npm packages and expands to Go ecosystem, targeting AI coding assistant persistence and GitHub Actions credential theft.
Mitiga — Poisoned Coding Test Turns AI Agent Into Attacker, 1,230+ Repos Leaking API Keys
Mitiga Labs scanned 50,000+ AI instruction files and found 1,230+ repos leaking API keys via poisoned CLAUDE.md and .cursor/rules — plus a real incident where a fake interview repo stole AWS credentials in under two minutes.
Mozilla 0DIN — Clean GitHub Repo Delivers Reverse Shell via AI Coding Agents
VentureBeat — Prompt Injection Exploits Enterprise AI Design Flaws Across Agents, RAG, and Model Routers
VentureBeat analysis shows prompt injection remains the top enterprise AI attack vector, targeting multi-agent architectures, RAG pipelines, and model routers with cross-model, memory, and context overflow techniques.
Microsoft — AutoJack RCE chain hijacks AutoGen Studio agents via MCP WebSocket
AutoJack is a three-bug chain in Microsoft AutoGen Studio where a malicious webpage hijacks a browsing AI agent into executing arbitrary commands on the developer host through an unauthenticated local MCP WebSocket.
Black Hat 2026 — First Copilot Sandbox Escape, AI Agent Exploitation & Offensive Models
Black Hat USA 2026 briefings reveal the first Copilot sandbox escape, trust-handoff failures across major AI vendors, and a 30B open-source model that outperforms frontier LLMs at agent exploitation.
Microsoft — The state of MCP security in 2026: OAuth, supply chain, and shadow servers
BioShocking — LayerX Breaks Guardrails in Six AI Browsers via Context Manipulation
DevFortress — The 2026 AI Agent Credential Crisis: 28M Secrets, 200K Vulnerable Servers
Six months of AI agent credential incidents: 28M new secrets on GitHub, 200K+ vulnerable MCP servers, 47K machines backdoored via LiteLLM, and the governance gap nobody has filled.
MCP 2026-07-28 Specification — Akamai Maps New Attack Surfaces After Security Overhaul
The upcoming MCP 2026-07-28 specification removes old protocol-level risks but shifts security responsibility to developers, introducing workflow hijacking, header desync, stored XSS, and DoS vectors.
OpenAI — GPT-5.6 Sol Restricted to Government-Approved Users After White House Cyber Review
OpenAI limits GPT-5.6 Sol access to vetted partners under unprecedented White House cybersecurity review process.
Unit 42 — ClawHub Evasive Skills Deploy Infostealers and Agentic Financial Fraud
Palo Alto Unit 42 found five malicious OpenClaw skills bypassing ClawScan and VirusTotal with size-based evasion, runtime affiliate injection, and novel agentic financial fraud.
AIR — Malicious AI Agent Skill Bypassed Cisco, NVIDIA Scanners, Reached 26,000 Users
AI risk firm AIR demonstrated that a malicious agent skill passed security scanners from Cisco, NVIDIA, and skills.sh, then reached 26,000 users via Instagram ads.