Posts
High-signal AI/security/automation notes.
Zentera MCP Security Enterprise Guide — Model-Directed Tool Calls Expand Attack Surface
curl 8.21.0 — AI-Powered AISLE Platform Finds 6 CVEs Including 25-Year-Old mTLS Flaw in Record Release
AI-powered security platform AISLE discovered 6 of 18 CVEs in curl 8.21.0 — the most vulnerabilities ever fixed in a single curl release — including a 25-year-old mTLS authentication bypass.
CVE-2026-53923 — vLLM GGUF Dequantization Bug Leaks GPU Memory Between Tenants
DeepMind AI Control Roadmap — Defense-in-Depth for Securing AI Agents
Google DeepMind publishes AI Control Roadmap treating agents as potential insider threats, with layered detection, prevention, and response controls.
LangGraph SQL Injection to RCE — Checkpointer Chain Exposes Agent State
AIR — Fake AI Agent Skill Bypassed All Scanners, Reached 26,000 Agents
Security firm AIR demonstrates that agent skill scanners miss post-review payload swaps via external links, reaching thousands of agents including corporate accounts.
Cordyceps CI/CD Flaw Exposes Google AI Agent Kit, Microsoft, Apache Repos
Systemic GitHub Actions vulnerability class lets anonymous attackers hijack pipelines at Microsoft, Google AI Agent Development Kit, Apache, Cloudflare, and Python Software Foundation.
DifyTap — Four CVEs Expose Cross-Tenant AI Chats on 1M+ App Platform
Zafran Security discloses DifyTap flaws enabling unauthenticated cross-tenant data theft in popular agentic AI platform.
OpenAI Daybreak — GPT-5.5-Cyber and Codex Security Plugin for Vulnerability Patching
OpenAI expands Daybreak initiative with GPT-5.5-Cyber model and Codex Security plugin to find, validate, and patch vulnerabilities at machine speed.
OWASP MCP Top 10 — First Protocol-Specific AI Agent Risk Framework
OWASP releases first MCP Top 10 framework as 30+ CVEs hit in early 2026, with 78.3% attack success rate and 82% path traversal exposure across MCP servers.
pgAdmin AI Assistant Bypass Enables RCE via Prompt Injection
CVE-2026-12045 (CVSS 9.0) in pgAdmin 4 allows attackers to bypass AI Assistant read-only transaction protections and execute arbitrary commands via prompt injection.
Cyberpress — 23 ClawHub Plugins Found Impersonating Official @openclaw and @clawhub Namespaces
Manifold Security discovers 23 ClawHub plugins squatting on official organizational scopes, highlighting supply chain risks in AI agent plugin ecosystems.
x41 Security — CVE-2026-48746 vLLM Authentication Bypass Affects Versions 0.3.0–0.22.0
CVE-2026-5027 — 7,000 Langflow Instances Under Active Attack via Path Traversal to RCE
vLLM — CVE-2026-54236 Exposes Sensitive Data via Incomplete Log Sanitization Fix
CVE-2026-54236 reveals that certain vLLM API routes and WebSocket handlers bypass global exception sanitization, leaking memory addresses and sensitive information in logs prior to v0.23.1rc0.
JetBrains IDE Plugins — 15 Malicious Add-ons Caught Stealing AI API Keys
A coordinated campaign of 15 JetBrains IDE plugins published under seven vendor accounts exfiltrates AI provider API keys to an attacker-controlled server, with ~70,000 installs since October 2025.
SecurityWeek — North Korean Sapphire Sleet Hits 140+ Mastra AI Agent Packages in NPM Supply Chain Attack
North Korean state-sponsored Sapphire Sleet compromised the Mastra AI agent framework via NPM supply chain attack, injecting crypto-targeting malware into 141 packages.
Open WebUI CVE Cluster — Auth Bypass, Data Exposure, and Path Traversal
OrcaRouter — AI Threat Report 2026 and Free Agent Firewall for Prompt Injection Defense
OrcaRouter publishes its AI Threat Report 2026 covering 14 key risks across four categories, and makes its agent Firewall and input/output Guardrails free for all users.