arXiv — Lifecycle & Application-Stack Survey of LLM Vulnerabilities (WPI SoK)
WPI researchers publish the first lifecycle and application-stack SoK of LLM vulnerabilities, mapping attacks across eight stages from data collection to agent execution.
High-signal AI/security/automation notes.
WPI researchers publish the first lifecycle and application-stack SoK of LLM vulnerabilities, mapping attacks across eight stages from data collection to agent execution.
Cato AI Labs discloses DuneSlide, two CVSS 9.8 flaws in Cursor IDE that let prompt injection overwrite the sandbox binary and achieve zero-click RCE.
Sysdig documents JADEPUFFER, an LLM agent that ran a full ransomware campaign from Langflow RCE to production database extortion — autonomously.
AI agents pull packages past scanners, enabling PromptMink, slopsquatting, and Clinejection attacks that bypass human review entirely.
Adversa AI discovers GuardFall, a class of shell injection bypasses where decades-old Bash quoting tricks defeat pattern-based guards in popular open-source AI coding agents.
Anthropic redeploys Fable 5 globally after export controls lifted, alongside a new cross-industry jailbreak severity framework developed with Amazon, Microsoft, and Google.
Apple pulled 29 WebKit security fixes forward from the iOS 26.6 cycle, citing AI-driven attack speed as the reason for breaking its traditional patch cadence.
LayerX researchers demonstrate BioShocking, a prompt injection technique that tricks six AI browsers into abandoning safety guardrails by establishing a fictional context — affecting ChatGPT Atlas, Comet, Fellou, Genspark, Sigma, and Claude Chrome.
Adversa AI reveals GuardFall, a structural flaw where decades-old Bash shell tricks bypass pattern-based guards in open-source AI coding agents, turning malicious repos into supply chain attack vectors.
Microsoft research demonstrates how attackers can hijack enterprise AI agents through poisoned MCP tool descriptions, triggering silent data exfiltration without breaking any access rules.
Unit 42 found 250,000 unregistered domains hallucinated by LLMs — adversaries are pre-registering them to intercept AI-agent traffic.
Critical sandbox escape in Cursor AI editor chains prompt injection through MCP manipulation to achieve arbitrary code execution on developer machines.
New Djinn Stealer deployed via SimpleHelp RMM exploit specifically harvests MCP configs, AI coding assistant tokens, and cloud credentials from developer machines.
The biggest MCP rewrite since launch removes session IDs to fix session hijacking but shifts authentication and authorization decisions to server implementers.
Two Chrome ad-blocker extensions with 100K+ users have been caught silently exfiltrating full conversation histories from ChatGPT, Claude, Gemini, and five other AI platforms.
Rapid7 presented a White House policy paper arguing that CVE, CVSS, NVD, and KEV infrastructure were built for human-speed discovery and cannot keep pace with AI-driven vulnerability research.
Wake Forest study finds 282 of 444 iOS AI apps expose API keys or open relays in plaintext network traffic, enabling LLMjacking and unauthorized inference theft.
CVE-2026-33017 (CVSS 9.3) in Langflow allows unauthenticated RCE via Python code injection, actively exploited to deploy Monero cryptominers on AI infrastructure.