Posts
High-signal AI/security/automation notes.
Forbes — Gartner Tells CISOs to Block All AI Browsers as Prompt Injection Defenses Fail
Gartner advises blocking ChatGPT Atlas and Perplexity Comet as CrowdStrike reports prompt injection at 90+ organizations and AI-enabled attacks surge 89%.
Miasma — LeoPlatform Supply Chain Attack Expands to Go, Targets AI Coding Assistants
Miasma malware compromises 23 LeoPlatform npm packages and expands to Go ecosystem, targeting AI coding assistant persistence and GitHub Actions credential theft.
Mitiga — Poisoned Coding Test Turns AI Agent Into Attacker, 1,230+ Repos Leaking API Keys
Mitiga Labs scanned 50,000+ AI instruction files and found 1,230+ repos leaking API keys via poisoned CLAUDE.md and .cursor/rules — plus a real incident where a fake interview repo stole AWS credentials in under two minutes.
Mozilla 0DIN — Clean GitHub Repo Delivers Reverse Shell via AI Coding Agents
VentureBeat — Prompt Injection Exploits Enterprise AI Design Flaws Across Agents, RAG, and Model Routers
VentureBeat analysis shows prompt injection remains the top enterprise AI attack vector, targeting multi-agent architectures, RAG pipelines, and model routers with cross-model, memory, and context overflow techniques.
Microsoft — AutoJack RCE chain hijacks AutoGen Studio agents via MCP WebSocket
AutoJack is a three-bug chain in Microsoft AutoGen Studio where a malicious webpage hijacks a browsing AI agent into executing arbitrary commands on the developer host through an unauthenticated local MCP WebSocket.
Black Hat 2026 — First Copilot Sandbox Escape, AI Agent Exploitation & Offensive Models
Black Hat USA 2026 briefings reveal the first Copilot sandbox escape, trust-handoff failures across major AI vendors, and a 30B open-source model that outperforms frontier LLMs at agent exploitation.
Microsoft — The state of MCP security in 2026: OAuth, supply chain, and shadow servers
BioShocking — LayerX Breaks Guardrails in Six AI Browsers via Context Manipulation
DevFortress — The 2026 AI Agent Credential Crisis: 28M Secrets, 200K Vulnerable Servers
Six months of AI agent credential incidents: 28M new secrets on GitHub, 200K+ vulnerable MCP servers, 47K machines backdoored via LiteLLM, and the governance gap nobody has filled.
MCP 2026-07-28 Specification — Akamai Maps New Attack Surfaces After Security Overhaul
The upcoming MCP 2026-07-28 specification removes old protocol-level risks but shifts security responsibility to developers, introducing workflow hijacking, header desync, stored XSS, and DoS vectors.
OpenAI — GPT-5.6 Sol Restricted to Government-Approved Users After White House Cyber Review
OpenAI limits GPT-5.6 Sol access to vetted partners under unprecedented White House cybersecurity review process.
Unit 42 — ClawHub Evasive Skills Deploy Infostealers and Agentic Financial Fraud
Palo Alto Unit 42 found five malicious OpenClaw skills bypassing ClawScan and VirusTotal with size-based evasion, runtime affiliate injection, and novel agentic financial fraud.
AIR — Malicious AI Agent Skill Bypassed Cisco, NVIDIA Scanners, Reached 26,000 Users
AI risk firm AIR demonstrated that a malicious agent skill passed security scanners from Cisco, NVIDIA, and skills.sh, then reached 26,000 users via Instagram ads.
Amazon Q Developer — Malicious Repo MCP Config Steals Cloud Credentials (CVE-2026-12957)
NRT-Bench — Multi-Turn Jailbreaks Defeat LLM Agents in Safety-Critical Control Rooms
New arXiv benchmark shows adaptive multi-turn attacks reliably push LLM operator teams past safety limits in a simulated nuclear plant control room.
Huntress — EvilTokens AI PhaaS Platform Drives 1,380% Surge in Device Code Phishing
Huntress research reveals how AI-powered EvilTokens platform weaponized device code phishing to bypass MFA at scale, stealing Microsoft 365 tokens from 344 organizations.
SentinelOne — macOS.Gaslight: North Korean Implant Uses Prompt Injection to Blind AI Triage
A Rust-based macOS implant from DPRK-aligned actors embeds 38 fabricated system messages to hijack LLM-assisted malware analysis pipelines.
OWASP — Agentic Skills Top 10: First Security Framework for AI Agent Skill Ecosystems
OWASP launches the Agentic Skills Top 10 (AST10), documenting 10 critical security risks across OpenClaw, Claude Code, Cursor/Codex, and VS Code agent skill ecosystems after scanning 3,984 skills.