High-signal AI/security/automation notes.
CVE-2026-54236 reveals that certain vLLM API routes and WebSocket handlers bypass global exception sanitization, leaking memory addresses and sensitive information in logs prior to v0.23.1rc0.
A coordinated campaign of 15 JetBrains IDE plugins published under seven vendor accounts exfiltrates AI provider API keys to an attacker-controlled server, with ~70,000 installs since October 2025.
North Korean state-sponsored Sapphire Sleet compromised the Mastra AI agent framework via NPM supply chain attack, injecting crypto-targeting malware into 141 packages.
OrcaRouter publishes its AI Threat Report 2026 covering 14 key risks across four categories, and makes its agent Firewall and input/output Guardrails free for all users.
Security Boulevard analysis finds the MCP ecosystem has 973 packages with 71% single-maintainer, 45% failure rate across 150+ LLMs for AI-generated code, and 55.8% provable vulnerability rate in formal verification.
SpecterOps demonstrates how SQL Server 2025 native AI features — sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, AI_GENERATE_EMBEDDINGS — can be abused for stealthy data exfiltration and covert C2 channels.
CVE-2026-41523 and CVE-2026-54235 reveal how assert-based security checks and float validation gaps in vLLM enable RCE and GPU kernel manipulation.
Tenet Security demonstrates Agentjacking: injected Sentry error events hijack AI coding agents via MCP, achieving 85% execution rate across Claude Code, Cursor, and Codex.
CISA adds actively exploited LiteLLM command injection to KEV catalog; chained with Starlette CVE-2026-48710, it yields unauthenticated RCE on AI gateway hosts.
Socket researchers discovered 23 new malicious PyPI artifacts from the Shai-Hulud campaign, featuring split-staging loaders, native extension payloads, and LLM anti-analysis tricks targeting MCP developers.
A new arXiv paper presents FORGE, a multi-agent system that bridges exploit generation, vulnerability prioritization, and detection engineering across 603 CVEs.
Brave researchers demonstrated indirect prompt injection attacks against both a cloud-hosted AI browsing API and a local macOS assistant, proving neither deployment model is immune.
AWS AgentCore CLI (CVSS 9) lets an authenticated account member inject arbitrary Python into generated agent source files via triple-quote escaping bypass.
A critical RCE flaw in Hugging Face Transformers lets attackers execute code via a poisoned config.json field, bypassing trust_remote_code=False.
Microsoft expanded its AI agent failure taxonomy with seven new critical attack vectors, including MCP/plugin abuse, session context contamination, and gradual reasoning bias injection.
OWASP released a risk-quadrant maturity framework for agentic AI, mapping autonomy against governance to flag high-risk deployments as red cells.
Varonis Threat Labs tricked an OpenClaw email agent into forwarding AWS IAM keys, database passwords, and CRM exports to an attacker after receiving a convincing phishing email.