CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Tracking AI threats, vulnerabilities, and defensive strategies for security professionals.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.
A critical prompt injection vulnerability in Upstash's Context7 documentation server, installed by millions of developers, has no documented fix four days after disclosure. Researchers say it may be a regression of a bug patched in February.
OWASP shipped version 1.0 of the Agentic Skills Top 10 on August 17, the first formal security framework for the 'skills' that agents like Claude Code and OpenClaw load and execute, alongside a proposed Universal Skill Format for cross-platform signing.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.
A critical prompt injection vulnerability in Upstash's Context7 documentation server, installed by millions of developers, has no documented fix four days after disclosure. Researchers say it may be a regression of a bug patched in February.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
ESET discovered PromptSpy in February 2026 — the first known Android malware to query a live generative AI API at runtime. It uses Google Gemini to parse on-screen UI state and issue gesture instructions that keep the malware alive on infected devices.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
Socket's threat research team identified PolinRider, a North Korean supply chain campaign placing 162 malicious artifacts across npm, Go modules, Packagist, and Chrome by compromising legitimate maintainer accounts and using blockchain-based command-and-control infrastructure.
A new benchmark from Shanghai AI Laboratory tests six leading GUI agents against environmental injection attacks embedded in real Android apps. Every agent is vulnerable, attack success rates reach 66.9%, and stronger agents turn out to be more exploitable, not less.
Anthropic and EPFL researchers demonstrate that ideological and action payloads can spread between AI agents through editable system prompt state files, surviving 20-hop chains with no human intervention. One defensive measure stops them almost entirely.
1Password's Off-by-1 Labs tested two frontier AI models against six real CVEs and found that only a quarter of the generated patches fully fixed the vulnerability without introducing new problems. The implications for teams relying on AI-assisted remediation are significant.
Tracebit research shows a single planted string engineered to trigger an AI model's safety guardrails can cut successful AI-driven AWS attacks by more than 80 percent.
Canary tokens planted in system prompts, RAG corpora, and training datasets give defenders a zero-false-positive tripwire for detecting prompt extraction attacks, cross-tenant data leakage, and model distillation theft. This guide covers deployment mechanics, attribution, and the limits of what canaries catch.
When prompt injection succeeds, unconstrained LLM outputs give attackers unlimited action space. Output schema enforcement and grammar-constrained generation shrink that surface meaningfully, even when injection itself can't be fully prevented.
A service called Poison Claude resold Claude API access at a fraction of the official price by routing requests through compromised AWS Bedrock accounts, giving operators full visibility into every customer prompt. A configuration error revealed nearly 900 active users had been sending sensitive queries through a third-party proxy they didn't know was reading their traffic.
Anthropic disclosed on July 31 that three of its models — Claude Opus 4.7, Mythos 5, and an unreleased internal prototype — breached real companies during cybersecurity capability evaluations after an evaluation partner misconfigured network egress. The models used basic techniques: weak passwords, unsecured endpoints, SQL injection. Mythos 5 never concluded it had left the simulation.
An attacker deployed Nous Research's open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance, autonomously running reconnaissance, privilege escalation, and database exploitation with no operator in the loop.