Posts
High-signal AI/security/automation notes.
NRT-Bench — Multi-Turn Jailbreaks Defeat LLM Agents in Safety-Critical Control Rooms
New arXiv benchmark shows adaptive multi-turn attacks reliably push LLM operator teams past safety limits in a simulated nuclear plant control room.
Huntress — EvilTokens AI PhaaS Platform Drives 1,380% Surge in Device Code Phishing
Huntress research reveals how AI-powered EvilTokens platform weaponized device code phishing to bypass MFA at scale, stealing Microsoft 365 tokens from 344 organizations.
SentinelOne — macOS.Gaslight: North Korean Implant Uses Prompt Injection to Blind AI Triage
A Rust-based macOS implant from DPRK-aligned actors embeds 38 fabricated system messages to hijack LLM-assisted malware analysis pipelines.
OWASP — Agentic Skills Top 10: First Security Framework for AI Agent Skill Ecosystems
OWASP launches the Agentic Skills Top 10 (AST10), documenting 10 critical security risks across OpenClaw, Claude Code, Cursor/Codex, and VS Code agent skill ecosystems after scanning 3,984 skills.
PixelSmash (CVE-2026-8461) — FFmpeg RCE Hits vLLM and AI Video Pipelines
Zentera MCP Security Enterprise Guide — Model-Directed Tool Calls Expand Attack Surface
curl 8.21.0 — AI-Powered AISLE Platform Finds 6 CVEs Including 25-Year-Old mTLS Flaw in Record Release
AI-powered security platform AISLE discovered 6 of 18 CVEs in curl 8.21.0 — the most vulnerabilities ever fixed in a single curl release — including a 25-year-old mTLS authentication bypass.
CVE-2026-53923 — vLLM GGUF Dequantization Bug Leaks GPU Memory Between Tenants
DeepMind AI Control Roadmap — Defense-in-Depth for Securing AI Agents
Google DeepMind publishes AI Control Roadmap treating agents as potential insider threats, with layered detection, prevention, and response controls.
LangGraph SQL Injection to RCE — Checkpointer Chain Exposes Agent State
AIR — Fake AI Agent Skill Bypassed All Scanners, Reached 26,000 Agents
Security firm AIR demonstrates that agent skill scanners miss post-review payload swaps via external links, reaching thousands of agents including corporate accounts.
Cordyceps CI/CD Flaw Exposes Google AI Agent Kit, Microsoft, Apache Repos
Systemic GitHub Actions vulnerability class lets anonymous attackers hijack pipelines at Microsoft, Google AI Agent Development Kit, Apache, Cloudflare, and Python Software Foundation.
DifyTap — Four CVEs Expose Cross-Tenant AI Chats on 1M+ App Platform
Zafran Security discloses DifyTap flaws enabling unauthenticated cross-tenant data theft in popular agentic AI platform.
OpenAI Daybreak — GPT-5.5-Cyber and Codex Security Plugin for Vulnerability Patching
OpenAI expands Daybreak initiative with GPT-5.5-Cyber model and Codex Security plugin to find, validate, and patch vulnerabilities at machine speed.
OWASP MCP Top 10 — First Protocol-Specific AI Agent Risk Framework
OWASP releases first MCP Top 10 framework as 30+ CVEs hit in early 2026, with 78.3% attack success rate and 82% path traversal exposure across MCP servers.
pgAdmin AI Assistant Bypass Enables RCE via Prompt Injection
CVE-2026-12045 (CVSS 9.0) in pgAdmin 4 allows attackers to bypass AI Assistant read-only transaction protections and execute arbitrary commands via prompt injection.
Cyberpress — 23 ClawHub Plugins Found Impersonating Official @openclaw and @clawhub Namespaces
Manifold Security discovers 23 ClawHub plugins squatting on official organizational scopes, highlighting supply chain risks in AI agent plugin ecosystems.