High-signal AI/security/automation notes.
Anthropic splits its Mythos-class model into two tiers: unrestricted Mythos 5 for vetted cyber professionals and safeguarded Fable 5 that falls back to Opus 4.8 for cybersecurity queries.
Poise achieves 89.3% attack success rate on LLM agent skills by exploiting position-aware injection — and bypasses current scanner defenses through false-positive blending.
CISA added CVE-2026-42271 (LiteLLM command injection) to its Known Exploited Vulnerabilities catalog on June 8, 2026 — confirming active exploitation of the chained BadHost RCE chain against AI serving infrastructure.
University of Toronto researchers built an AI-powered worm using free local LLMs that self-replicated across 27 of 33 systems in a simulated enterprise network over five generations.
Check Point discloses CVE-2026-50751, a critical IKEv1 authentication bypass actively exploited since May by Qilin ransomware; CISA adds it to the KEV catalog.
Docker publishes real-world case studies of AI agents destroying user data outside sandboxed workspaces, including a Claude Cowork incident that deleted 15,000+ photos.
Threat actors use Google Sites-hosted fake Claude Code and OpenAI Codex installer pages to trick developers into running credential-stealing commands.
An autonomous AI agent found 21 previously unknown vulnerabilities in FFmpeg, including bugs latent for up to 23 years, at a cost of roughly $1,000 per scan run.
NVIDIA released SkillSpector, an open-source security scanner that detects 64 vulnerability patterns across 16 categories in AI agent skills before installation.
A critical OS command injection vulnerability (CVSS 9.8) in radare2-mcp allows unauthenticated remote attackers to execute arbitrary commands via the JSON-RPC interface.
A new Hades-family wave of the Shai-Hulud supply chain campaign compromises 23 PyPI packages with MCP-themed typosquats and a novel LLM anti-analysis technique.
A June 2026 US executive order directs an AI cybersecurity clearinghouse, CISA guidance for AI-enabled defenses, and federal system upgrades within 30 days.
Anthropic expands Project Glasswing to ~200 organizations across 15+ countries; Claude Mythos Preview has surfaced over 10,000 high- and critical-severity vulnerabilities in widely used software, with first public CVE wave expected July 2026.
Opening an attacker-supplied .NET solution in the Roslyn CodeLens MCP server loads and executes arbitrary code, turning code-intelligence tooling into a remote-code-execution vector.
A flag-injection flaw in mcp-server-kubernetes lets attacker-controlled logs exfiltrate operator K8s bearer tokens via indirect prompt injection.