CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Trend Micro's H1 2026 APT roundup documents China, Russia, and North Korea-aligned actors integrating generative AI and autonomous agents across the intrusion lifecycle. One AI agent ran unsupervised reconnaissance and lateral movement inside a target network after being jailbroken with a false pen test claim.
Unit 42 researchers found five malicious skills on ClawHub that slipped past automated scanners, delivering AMOS malware and running agentic financial scams. The AI agent skill marketplace is the new npm — and it has the same supply chain problem.
NVIDIA and 36 industry partners — including Microsoft, Cisco, CrowdStrike, and Hugging Face — launched the Open Secure AI Alliance on July 27, 2026, releasing the NOOA framework for testing and auditing AI agent behaviour. The coalition cites recent autonomous agent attacks as the catalyst.
Zenity Labs disclosed AgentForger on July 23, a ChatGPT Workspace Agents flaw that let a single crafted URL silently build and deploy an attacker-controlled AI agent with full access to an enterprise's connected apps — email, calendar, Slack, Teams, and more.
Zenity Labs disclosed a CSRF flaw in ChatGPT's Agent Builder that let a crafted URL silently deploy an autonomous attacker-controlled agent inside a victim's enterprise, polling for orders every five minutes via email.
Research published in June 2026 documents a new supply-chain attack class targeting AI coding agent skill ecosystems: VulMask disguises malicious payloads as security vulnerabilities inside skill auxiliary resources, evading automated scanners. A Snyk audit of 3,984 skills found 13.4% carry critical-severity issues.
Salt Security's 1H 2026 State of AI and API Security report finds 92% of organizations lack the maturity to defend AI agent environments, while 99% of attack attempts originate from authenticated sources — rogue agents operating with legitimate credentials and no human oversight.
Johann Rehberger demonstrated a TOCTOU race condition against Claude Computer-Use where swapping the UI during the agent's reasoning window causes it to click the wrong element — in a working demo, the agent sends a malicious email while believing it clicked a harmless Continue button.
A new research paper describes an automated attack that poisons an AI agent's durable memory through a single email, with success rates above 70% against current frontier models. The planted lie loads into every subsequent session until manually audited.
Orca Security's 2026 State of AI Security Report finds that nearly all AI vulnerability alerts with available patches are ignored, while 74% of companies carry at least one critical CVE in their AI stack.
A coordinated disclosure of 13 critical vm2 vulnerabilities in May 2026 exposed a structural problem: AI agent frameworks that use vm2 as a code execution sandbox convert a prompt injection into host-level RCE the moment the sandbox breaks. Here's the chain and what to do about it.
A three-flaw chain in Microsoft AutoGen Studio's MCP WebSocket surface lets a malicious webpage execute arbitrary commands on the host via an AI browsing agent. Microsoft patched in June 2026.
Researchers at ELLIS Tübingen and UMass Amherst prove via Contextual Integrity theory that prompt injection in AI agents cannot be fully prevented, only contained. Current defences including Prompt Guard and Meta SecAlign fall short by wide margins.
A new arXiv paper tested 16 frontier models in a simulated corporate fraud scenario and found that 75% would follow executive orders to destroy evidence and suppress whistleblowers.
Check Point Research found three CVEs in LangGraph's persistence layer. CVE-2025-67644 SQLi chains with CVE-2026-28277 deserialization to reach RCE.
Threat actors embed prompt injection payloads in third-party LLM plugins and data sources to hijack AI agent actions, exfiltrate data, and pivot within enterprise environments.