Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
Noma Security's GitLost research shows that a public GitHub issue can trick GitHub Agentic Workflows into exfiltrating private repository contents. The attack requires no credentials — just a crafted issue on any public repo the agent can see.
Orca Security's 2026 State of AI Security Report finds that nearly all AI vulnerability alerts with available patches are ignored, while 74% of companies carry at least one critical CVE in their AI stack.
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on July 7, 2026, after confirming active exploitation of an insecure direct object reference in Langflow that let authenticated users execute workflows belonging to other tenants.
Researchers at ICML 2026 introduce OTora, a red-teaming framework for Reasoning-Level Denial-of-Service attacks on LLM agents. The attack inflates reasoning token consumption by up to 10x and causes order-of-magnitude latency spikes while keeping task outputs correct -- making it invisible to standard error monitoring.