Zenity Labs expanded its PleaseFix research at Black Hat 2026, showing how crafted emails and social posts can silently hijack Claude, ChatGPT Atlas, Gemini, Perplexity Comet, and Copilot Edge with no user interaction required.
CVEs, exploits, and security flaws in AI frameworks, models, and infrastructure.
Zenity Labs expanded its PleaseFix research at Black Hat 2026, showing how crafted emails and social posts can silently hijack Claude, ChatGPT Atlas, Gemini, Perplexity Comet, and Copilot Edge with no user interaction required.
Novee Security disclosed CVE-2026-54316 at Black Hat USA 2026: a zero-privilege GitHub issue can reach CI runner secrets across Claude Code, Gemini CLI, and OpenAI Codex. The Claude Code variant eventually exfiltrated secrets one character at a time via Hugging Face download counters. A separate Gemini CLI flaw scored CVSS 10.0.
CVE-2026-41264 in Flowise's CSVAgent node lets an attacker upload a crafted CSV file, inject a prompt that directs the LLM to generate malicious Python, and execute that code on the host with no authentication required. Metasploit module landed July 11, 2026.
Varonis disclosed at DEF CON 34 that Atlassian Rovo's URL parameter pre-fills the AI agent with attacker-controlled prompts, enabling a one-click attack that directs Rovo's ResearchAgent to exfiltrate Jira, Confluence, Slack, and M365 data to an attacker URL.
CVE-2026-18948 (CVSS 9.9) exploits Python dill deserialization to achieve unauthenticated RCE on Feast feature servers. CVE-2026-23537 (CVSS 9.1) allows arbitrary file writes via the /save-document endpoint. Together they expose ML pipelines to full compromise.