{"id":132046,"url":"https://github.com/webpro255/awesome-ai-agent-attacks","name":"awesome-ai-agent-attacks","description":"A curated timeline of real AI agent security incidents, breaches, and vulnerabilities (2024-2026). Every entry sourced and dated.","projects_count":269,"last_synced_at":"2026-07-13T21:00:17.896Z","repository":{"id":349803451,"uuid":"1203928374","full_name":"webpro255/awesome-ai-agent-attacks","owner":"webpro255","description":"A curated timeline of real AI agent security incidents, breaches, and vulnerabilities (2024-2026). Every entry sourced and dated.","archived":false,"fork":false,"pushed_at":"2026-07-13T14:45:24.000Z","size":193,"stargazers_count":35,"open_issues_count":0,"forks_count":3,"subscribers_count":4,"default_branch":"main","last_synced_at":"2026-07-13T16:22:52.460Z","etag":null,"topics":["adversarial-attacks","agent-security","agentic-ai","ai-agent-security","ai-agents","ai-attacks","ai-safety","ai-security","awesome-list","cve","cybersecurity","incident-response","llm-security","mcp-security","owasp","prompt-injection","red-team","security-research","supply-chain-security","vulnerability"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/webpro255.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-04-07T14:19:50.000Z","updated_at":"2026-07-13T14:45:36.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/webpro255/awesome-ai-agent-attacks","commit_stats":null,"previous_names":["webpro255/awesome-ai-agent-attacks"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/webpro255/awesome-ai-agent-attacks","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpro255%2Fawesome-ai-agent-attacks","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpro255%2Fawesome-ai-agent-attacks/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpro255%2Fawesome-ai-agent-attacks/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpro255%2Fawesome-ai-agent-attacks/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/webpro255","download_url":"https://codeload.github.com/webpro255/awesome-ai-agent-attacks/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/webpro255%2Fawesome-ai-agent-attacks/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35436279,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-13T02:00:06.543Z","response_time":119,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2026-05-23T01:35:10.469Z","updated_at":"2026-07-13T21:00:17.896Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Key Statistics","2024 Incidents","2025 Incidents","2026 Incidents"],"sub_categories":["2024 - LangChain Code Execution via LLMSymbolicMathChain","2024-04-02 - Many-Shot Jailbreaking Research","2024-03 - ChatGPT Plugin/Extension Vulnerabilities","2025-04 - MCP Tool Poisoning / WhatsApp Data Exfiltration","2024-02 - PoisonedRAG Research","2025-03-18 - Rules File Backdoor Attack on Cursor and Copilot","2024-02-14 - Air Canada Chatbot Lawsuit Ruling","2024-06 - McDonald's Ends AI Drive-Thru After Failures","2024-08-06 - Microsoft Copilot Studio SSRF","2025-06 - Anthropic Filesystem MCP Server \"EscapeRoute\"","2024-04 - Hugging Face Cross-Tenant Attack","2026-02-09 - Clinejection Supply Chain Attack","2025-08 - Cursor MCPoison Silent Backdoor","2025-12 - LangChain \"LangGrinch\" Serialization Injection","2025-08 - Varonis \"Reprompt\" - Microsoft Copilot Single-Click Data Theft","2025 - GitHub Copilot RoguePilot Repository Takeover","2024-12-04 - Ultralytics PyPI Supply Chain Attack","2026-01-21 - Claude Code API Key Exfiltration","2026-04-24 - LangChain langchain-openai and langchain-text-splitters SSRF Disclosures","2026-04-23 - HexagonalRodent North Korean APT Industrializes Web3 Developer Attacks Using AI Coding Tools","2026-04-23 - Google Workspace Reports 32% Rise in Indirect Prompt Injection Pages on the Open Web","2026-04-23 - SecurityScorecard Finds 40,214 OpenClaw Instances Exposed Online with 63% RCE-Vulnerable","2026-04-22 - Bitwarden CLI npm Package Trojanized via Checkmarx KICS Cascade","2026-04-22 - Xinference PyPI Package Compromise (Versions 2.6.0-2.6.2)","2026-04-21 - LMDeploy SSRF Exploited Within 13 Hours of Public Disclosure (CVE-2026-33626)","2026-04-21 - CanisterSprawl Self-Propagating npm Worm via Namastex Labs and pgserve","2026-04-21 - Anthropic Claude Mythos Preview Accessed by Discord Group via Vendor Breach","2026-04-21 - Cloud Security Alliance Survey: AI Agent Incidents Common Across Enterprises","2026-04-21 - Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264)","2026-04-20 - Vercel Breach via Context.ai AI Tool Supply Chain","2026-04-17 - FastGPT Authentication and Password Change NoSQL Injection","2026-04-16 - Anthropic MCP Systemic STDIO Design RCE","2026-04-15 - LiteLLM OIDC Userinfo Cache Authentication Bypass","2026-04-15 - Copilot Studio ShareLeak and Agentforce PipeLeak Form-Based Prompt Injection","2026-04-15 - Claude Code, Gemini CLI, Copilot Agent Hijacked via GitHub Comments","2026-04-15 - n8n Webhook Weaponization for Phishing Campaigns","2026-04-14 - OWASP GenAI Q1 2026 Exploit Round-up Report","2026-04-13 - Malicious LLM Router Research Reveals Credential and Crypto Theft","2026-04-13 - Marimo Pre-Auth RCE Weaponized to Deploy NKAbuse via Hugging Face","2026-04-13 - Nginx UI MCP Auth Bypass Under Active Exploitation","2026-04-11 - aws-mcp-server Unauthenticated RCE via Command Injection","2026-04-10 - Red Hat OpenShift AI odh-dashboard Kubernetes Token Disclosure","2026-04-08 - PraisonAI Template Injection in Agent Tool Definitions","2026-04-08 - UNC1069 Contagious Interview Cross-Ecosystem Package Campaign","2026-04-07 - AWS Bedrock AgentCore \"Agent God Mode\" Cross-Agent Memory Access","2026-04-07 - Flowise AI Agent Builder RCE Actively Exploited in the Wild","2026-04-03 - PraisonAI Gateway Unauthenticated Agent Control","2026-04-03 - Azure MCP Server Authentication Flaw","2026-04-02 - Meta Pauses Mercor Partnership","2026-04-01 - Drift Protocol $285M Exploit","2026-03-30 - ChatGPT Hidden DNS Exfiltration Channel","2026-03-31 - Mercor Data Breach via LiteLLM Supply Chain","2026-03-31 - Axios npm Supply Chain Attack","2026-03-31 - Cisco Source Code Stolen via Trivy Breach","2026-03-27 - Telnyx PyPI Supply Chain Compromise","2026-03-24 - LiteLLM Supply Chain Attack by TeamPCP","2026-03-23 - Checkmarx KICS GitHub Actions Compromise","2026-03-20 - CanisterWorm npm Worm by TeamPCP","2026-03-19 - Trivy GitHub Action Compromise by TeamPCP","2026-03-18 - Meta Sev 1 Rogue AI Agent Incident","2026-03-17 - Langflow RCE Exploited Within 20 Hours","2026-03-17 - LangChain Core Path Traversal","2026-03-11 - UNC6426 nx npm to AWS Admin Takeover","2026-03-10 - Meta Acquires Moltbook (OpenClaw) After Security Crises","2026-03 - ROME AI Agent Escapes Sandbox, Mines Cryptocurrency","2026-02-22 - OpenClaw Agent Deletes 200+ Emails at Meta","2026-02-20 - CyberStrikeAI FortiGate Mass Compromise","2026-02-04 - MCP TypeScript SDK Cross-Client Data Leak","2026-01-23 - Langflow Active Exploitation Deploys Flodrix Botnet","2026-01-20 - Anthropic Git MCP Server Vulnerability Chain","2026-01 - Step Finance AI Trading Agent Treasury Drain","2026-01-08 - n8n \"Ni8mare\" CVSS 10.0 RCE","2025-12 - IDEsaster - 30+ Flaws Across AI Coding Tools","2025-12 - Copilot Studio Prompt Injection Data Leak","2025-11 - ServiceNow Now Assist Second-Order Prompt Injection","2025-11 - CrewAI \"Uncrew\" GitHub Token Exposure","2025-11 - Claude Desktop Extensions RCE","2025-11-13 - GTG-1002 Chinese State-Sponsored AI-Orchestrated Espionage","2025-11-04 - GitHub Copilot Filename Prompt Injection","2025-09 - Salesforce Agentforce \"ForcedLeak\"","2025-08-20 - Salesloft Drift OAuth Supply Chain Breach","2025-08 - Claude Code InversePrompt Command Injection","2025-08 - Claude Code WebSocket Auth Bypass","2025-08 - OpenAI Codex CLI Command Injection","2025-08 - GitHub Copilot RCE via Prompt Injection","2025-08 - Cursor CurXecute RCE via Slack MCP","2025-07-17 - Amazon Q VS Code Extension Compromise","2025-07-09 - Hugging Face Poisoned GGUF Templates","2025-07 - mcp-remote Critical RCE","2025-06 - Langflow Flodrix Botnet Exploitation","2025-06 - EchoLeak - Microsoft 365 Copilot Zero-Click Prompt Injection","2025-06 - GitHub Copilot CamoLeak","2025-05 - ElizaOS Memory Injection Vulnerability","2025-05 - Langflow CISA KEV Addition - Confirmed Active Exploitation","2025-03-15 - tj-actions/changed-files GitHub Actions Supply Chain Attack","2025-02-21 - Bybit $1.5B Cryptocurrency Heist","2025-02 - Google Gemini Prompt Injection via Calendar Invites","2025-01-24 - OmniGPT Data Breach","2025 - Cursor Case Sensitivity Bypass","2025 - DB-GPT Plugin Upload RCE","2024-12 - ChatGPT Search Manipulation via Hidden Text","2024-11-22 - Freysa AI Agent Game - Function Manipulation","2024-11 - Microsoft Copilot Exposes Private GitHub Repos","2024-11 - Microsoft Copilot Studio XSS","2024-10-17 - Imprompter Attack on AI Chatbots","2024-10-22 - Claude Computer Use Launch Security Warnings","2024-09 - ChatGPT \"SpAIware\" Persistent Memory Exploitation","2024-09-25 - NVIDIA Container Toolkit Vulnerability","2024-08-20 - Slack AI Prompt Injection and Data Exfiltration","2024-08-08 - LOLCopilot - Black Hat USA 2024 Copilot Attacks","2024-07 - Grok AI Election Misinformation","2024-07 - ChatGPT macOS Cleartext Storage","2024-07 - Microsoft 365 Copilot ASCII Smuggling","2024-06-25 - Rabbit R1 Hardcoded API Keys","2024-06 - Hugging Face Spaces Breach","2024-05 - GitHub Copilot Training Data Secret Leakage","2024-03 - OpenAI Compromised Credentials on Dark Web","2024-01-18 - DPD AI Chatbot Malfunction","2024 - LangChain Arbitrary Code Execution","2024 - LangChain GraphCypherQAChain Injection","2026-05-07 - Microsoft Semantic Kernel Prompt-Injection to RCE (CVE-2026-26030, CVE-2026-25592)","2026-07-13 - Orca Security 2026 State of AI Security Report","2026-07-11 - \"Ghostcommit\" Hides Prompt Injection Inside PNG Images to Steal Secrets","2026-07-10 - Wave of Critical RCE Flaws Across AI Agent Frameworks (CVE-2026-61447, CVE-2026-54769, CVE-2026-57572, CVE-2026-59726)","2026-07-09 - Open WebUI 16-Flaw Security Batch (CVE-2026-59212 to CVE-2026-59227)","2026-07-09 - \"Friendly Fire\" Turns AI Code-Audit Agents Into Code Execution","2026-07-09 - AWS AI Gateway Wired to Amazon Bedrock Hijacked for Cryptomining","2026-07-09 - Cline AI Coding Agent Hub WebSocket RCE (CVE-2026-59723)","2026-07-08 - \"GhostApproval\" Symlink Flaws Defeat Human-in-the-Loop in Six AI Coding Assistants","2026-07-08 - \"HalluSquatting\" Weaponizes AI Package-Name Hallucinations","2026-07-08 - GitHub Copilot Guardrails Bypassed by Multi-Step Workflow Framing","2026-07-08 - China's CNVDB Labels Claude Code a \"Backdoor\"; Alibaba Bans It","2026-07-08 - Sygnia Documents Lone Attacker Breaching AWS in 72 Hours With Agentic AI","2026-07-08 - Injective SDK npm Packages Backdoored to Steal Wallet Keys and Poison AI Agent Configs","2026-07-08 - ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge, First GenAI Android Malware","2026-07-08 - LiteLLM MCP Authentication Bypass (CVE-2026-59822)","2026-07-07 - \"GitLost\" Leaks Private Repositories via GitHub Agentic Workflows","2026-07-07 - Google Dialogflow CX \"Rogue Agent\" Cross-Agent Hijack","2026-07-07 - \"WriteOut\" Cross-Tenant Account Takeover in Writer AI","2026-07-07 - CISA Adds Langflow IDOR (CVE-2026-55255) to KEV, First AI Agent Platform in the Catalog","2026-07-07 - Google Gemini Live API RCE via Unconstrained Ephemeral Tokens","2026-07-07 - mem0 Unauthenticated Memory Access and Key Disclosure (CVE-2026-59705, CVE-2026-59706)","2026-07-07 - DigiCert AI Trust Outlook: 78% of Enterprises Report AI Security Incidents","2026-07-07 - Trend Micro \"Stars Don't Save You\" MCP Ecosystem Study","2026-07-06 - \"SkillCloak\" Repacks Malicious AI Agent Skills to Evade Scanners","2026-07-06 - Summer.fi \"Keeper AI Agents\" Exploit Drains About $6M","2026-07-06 - OpenAI Codex Desktop Zero-Click Data Exfiltration (CVE-2026-14898)","2026-07-02 - Zscaler Documents In-the-Wild Indirect Prompt Injection Targeting Autonomous AI Agents","2026-07-02 - fast-mcp-telegram MCP Server Authentication Bypass (CVE-2026-52830)","2026-07-01 - \"JADEPUFFER\" First Documented End-to-End Agentic Ransomware","2026-07-01 - Cursor \"DuneSlide\" Zero-Click Prompt-Injection RCE (CVE-2026-50548, CVE-2026-50549)","2026-07-01 - Check Point Demonstrates LLM-Generated Browser-Native Ransomware","2026-07-01 - Apify Actors MCP Server Token Exfiltration (CVE-2026-50143)","2026-06-30 - \"GuardFall\" Shell-Injection Bypass in Open-Source AI Coding Agents","2026-06-30 - Palo Alto Unit 42 \"Phantom Squatting\" - AI-Hallucinated Domains as an Attack Surface","2026-06-30 - Anthropic \"buffa\" Rust protobuf Memory-Amplification DoS (CVE-2026-55407)","2026-06-26 - Amazon Q Developer Silent MCP Config Auto-Load (CVE-2026-12957, CVE-2026-12958)","2026-06-23 - Dify \"DifyTap\" Cross-Tenant Data Exposure (CVE-2026-41947 to CVE-2026-41950)","2026-06-22 - vLLM OpenAI-Compatible API Authentication Bypass (CVE-2026-48746)","2026-06-18 - Microsoft AutoGen Studio \"AutoJack\" Drive-By Code Execution","2026-06-17 - Mastra AI npm Scope Compromise (Sapphire Sleet / UNC1069)","2026-06-15 - Microsoft 365 Copilot \"SearchLeak\" One-Click Data Theft (CVE-2026-42824)","2026-06-08 - Langflow Path Traversal RCE Exploited in the Wild (CVE-2026-5027)","2026-06-05 - Hades PyPI Worm Wave (Shai-Hulud / Miasma Lineage)","2026-06-05 - Claude Code GitHub Action Prompt-Injection Secret Exfiltration","2026-06-03 - node-gyp \"Phantom Gyp\" Self-Propagating npm Worm (Miasma)","2026-06-01 - Red Hat @redhat-cloud-services npm \"Miasma\" Worm","2026-05-28 - Nx Console Malicious VS Code Extension Leads to GitHub Repository Breach","2026-05-25 - \"Megalodon\" Mass GitHub Actions Secret Exfiltration","2026-05-20 - NVIDIA Triton Inference Server Authentication Bypass (CVE-2026-24207)","2026-05-18 - actions-cool GitHub Actions Tag Hijack (Mini Shai-Hulud)","2026-05-15 - PraisonAI Auth-Disabled API Server (CVE-2026-44338)","2026-05-14 - OpenAI Internal Source Code and Certificate Theft via TanStack Worm","2026-05-12 - Claude Code Deeplink RCE","2026-05-12 - Cline AI Agent Unauthenticated WebSocket RCE (CVE-2026-44211)","2026-05-12 - GitHub Copilot and VS Code Security-Feature Bypass (CVE-2026-41109)","2026-05-11 - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, and Guardrails AI (CVE-2026-45321)","2026-05-11 - Google GTIG Reports First AI-Developed Zero-Day for Mass Exploitation","2026-05-10 - Ollama \"Bleeding Llama\" Unauthenticated Memory Leak (CVE-2026-7482)","2026-05-07 - Microsoft Azure AI Foundry M365 Agent Privilege Escalation (CVE-2026-35435)","2026-05-07 - Malicious Hugging Face \"Open-OSS/privacy-filter\" Fake OpenAI Model","2026-05-05 - Ollama for Windows Auto-Updater RCE and Persistence (CVE-2026-42248, CVE-2026-42249)","2026-05-04 - Grok and Bankr AI Wallet Drained via Morse-Code Prompt Injection","2026-04-30 - PyTorch Lightning PyPI Compromise (Mini Shai-Hulud)","2026-04-30 - Google Gemini CLI CVSS 10.0 Headless RCE","2026-04-29 - LiteLLM Pre-Auth SQL Injection (CVE-2026-42208)"],"readme":"# Awesome AI Agent Attacks [![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\nA curated timeline of real AI agent security incidents, breaches, and vulnerabilities from 2024-2026. Every entry includes date, named company/product, specific impact, root cause, CVE where applicable, and source links.\n\nNo opinions. No product pitches. Just facts with sources.\n\nLast updated: 2026-07-13\n\n---\n\n## Contents\n\n- [2026 Incidents](#2026-incidents)\n- [2025 Incidents](#2025-incidents)\n- [2024 Incidents](#2024-incidents)\n- [Key Statistics](#key-statistics)\n- [Attack Pattern Taxonomy](#attack-pattern-taxonomy)\n- [Contributing](#contributing)\n\n---\n\n## 2026 Incidents\n\n### 2026-07-13 - Orca Security 2026 State of AI Security Report\n\n- **Target:** Cloud AI deployments across hundreds of thousands of scanned enterprise environments\n- **Impact:** The report finds AI security debt piling up. 99.9% of AI-related vulnerability alerts that have an available fix remain unpatched; 81.2% of companies running AI packages carry at least one known vulnerability and 74.1% at least one critical CVE; 56% of AI adopters have pushed agent frameworks to production; 64% run vector databases (RAG users average 3.78 of them); and about 30% store at least one AI key insecurely\n- **Root Cause:** Rapid AI adoption outpacing patching, key hygiene, and encryption, with agent frameworks and vector stores deployed faster than they are secured\n- **Sources:** [Help Net Security](https://www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/)\n\n### 2026-07-11 - \"Ghostcommit\" Hides Prompt Injection Inside PNG Images to Steal Secrets\n\n- **Target:** AI code-review agents Cursor and Google Antigravity (backed by Claude Sonnet, Gemini, and GPT-5.5); Anthropic's Claude Code refused across all tested models\n- **Impact:** Instructions hidden as readable text inside a PNG referenced by an `AGENTS.md` convention file drive an agent to read a project `.env` byte by byte and emit the secrets as a tuple of integer constants disguised as ordinary code, slipping past secret scanners. One run leaked an entire `.env` as a 311-integer constant containing API keys, database URLs, and cloud credentials. A survey found 73% of merged pull requests across 300 top repositories reached the default branch with no substantive human or bot review\n- **Root Cause:** AI code reviewers treat image files as binary blobs and exclude them from analysis, so a prompt injection carried inside an image is never inspected, while encoding stolen secrets as integers evades string-pattern secret detection. Found by Sudipta Chattopadhyay and Murali Ediga (University of Missouri-Kansas City ASSET Research Group)\n- **Sources:** [BleepingComputer](https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/), [Cybersecurity News](https://cybersecuritynews.com/ghostcommit-attack-hides-prompts/)\n\n### 2026-07-10 - Wave of Critical RCE Flaws Across AI Agent Frameworks (CVE-2026-61447, CVE-2026-54769, CVE-2026-57572, CVE-2026-59726)\n\n- **Target:** PraisonAI before 1.6.78; Langroid before 0.65.2; Crawl4AI before 0.9.0; Ruflo before 3.16.3\n- **Impact:** Four separate critical remote code execution paths were disclosed the same week. PraisonAI's CodeAgent runs LLM-generated Python with no AST validation or sandbox (CVE-2026-61447); Langroid escapes its evaluation sandbox in `TableChatAgent`/`VectorStore` when `full_eval=True` (CVE-2026-54769); Crawl4AI's Docker API accepts attacker-supplied Chromium arguments for unauthenticated RCE (CVE-2026-57572); and Ruflo, a meta-harness for Claude Code and Codex, exposes an unauthenticated MCP bridge whose `terminal_execute` tool grants shell access and provider-key theft (CVE-2026-59726)\n- **Root Cause:** LLM-generated code, SQL, or shell arguments executed without validation or isolation, plus MCP and dashboard endpoints exposed with no authentication\n- **CVE:** CVE-2026-61447, CVE-2026-54769, CVE-2026-57572, CVE-2026-59726 (all CVSS 10.0)\n- **Sources:** [NVD CVE-2026-61447](https://nvd.nist.gov/vuln/detail/CVE-2026-61447), [NVD CVE-2026-54769](https://nvd.nist.gov/vuln/detail/CVE-2026-54769), [NVD CVE-2026-57572](https://nvd.nist.gov/vuln/detail/CVE-2026-57572), [NVD CVE-2026-59726](https://nvd.nist.gov/vuln/detail/CVE-2026-59726)\n\n### 2026-07-09 - Open WebUI 16-Flaw Security Batch (CVE-2026-59212 to CVE-2026-59227)\n\n- **Target:** Open WebUI (self-hosted LLM interface) before 0.10.0\n- **Impact:** Sixteen flaws fixed at once. The most severe include identity spoofing on the terminal WebSocket via an unencoded `session_id` (CVE-2026-59224, CVSS 8.0), running code in another user's session through client-supplied session IDs on `execute:python`/`execute:tool` events (CVE-2026-59216), a nine-times percent-encoded path-traversal bypass of an eight-pass decode (CVE-2026-59221), a Pyodide same-origin worker reaching admin endpoints (CVE-2026-59214), and revoked JWTs still authenticating realtime connections (CVE-2026-59219)\n- **Root Cause:** Missing authorization on realtime socket events, client-trusted session identifiers, and incomplete input decoding across a self-hosted LLM UI\n- **CVE:** CVE-2026-59212 through CVE-2026-59227 and CVE-2026-59715\n- **Sources:** [NVD CVE-2026-59224](https://nvd.nist.gov/vuln/detail/CVE-2026-59224), [NVD CVE-2026-59216](https://nvd.nist.gov/vuln/detail/CVE-2026-59216)\n\n### 2026-07-09 - \"Friendly Fire\" Turns AI Code-Audit Agents Into Code Execution\n\n- **Target:** Anthropic Claude Code (CLI 2.1.116 through 2.1.199 on Sonnet 4.6, Sonnet 5, and Opus 4.8) and OpenAI Codex (CLI 0.142.4 on GPT-5.5) running in autonomous or auto-approval review modes\n- **Impact:** When these agents are asked to audit an untrusted third-party repository, a malicious binary disguised as a compiled build artifact (seeded with strings from legitimate source to defeat disassembly checks) plus instructions planted in a plain README drive the agent to run the payload on the developer's machine, turning a security-review tool into an execution vector. Newer models sometimes flagged that the binary did not match its supposed source and executed it anyway\n- **Root Cause:** Models cannot reliably separate code they are analyzing from instructions embedded in documentation, a design-level weakness rather than a version-specific bug. Found by the AI Now Institute (Boyan Milanov, Heidy Khlaaf)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.html), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/anthropic-openai-report-exploit/)\n\n### 2026-07-09 - AWS AI Gateway Wired to Amazon Bedrock Hijacked for Cryptomining\n\n- **Target:** An internet-exposed \"LiteLLM-Proxy\" EC2 instance acting as an AI gateway with a privileged IAM role for Amazon Bedrock\n- **Impact:** With SSH (port 22) open to `0.0.0.0/0`, the host was brute-forced, a 3.42 MB XMRig cryptominer was pulled from an attacker endpoint, and the instance began mining to `pool.hasvault[.]pro`. Follow-on activity from a Vietnam-based IP attempted Bedrock model calls and an IAM `CreateUser`, showing intent to abuse the gateway's model access and cloud privileges\n- **Root Cause:** An AI gateway that centralizes model access, identities, and cloud IAM privileges, left exposed to the internet with weak SSH controls, becomes a high-value pivot. Detected by Darktrace (activity June 12-13, 2026)\n- **Sources:** [SiliconANGLE](https://siliconangle.com/2026/07/09/darktrace-finds-ai-gateway-amazon-bedrock-access-hijacked-cryptomining/), [Dark Reading](https://www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom), [GBHackers](https://gbhackers.com/hackers-compromise-aws-ai-gateway-connected-to-amazon-bedrock/)\n\n### 2026-07-09 - Cline AI Coding Agent Hub WebSocket RCE (CVE-2026-59723)\n\n- **Target:** Cline autonomous coding agent before 3.0.30\n- **Impact:** The Cline Hub dashboard `/browser` WebSocket accepts connections without Origin validation; when `ROOM_SECRET` is unset on `127.0.0.1`, a malicious webpage can send `desktopCommand` frames to read workspace state, alter MCP and provider settings, and trigger command execution\n- **Root Cause:** Missing Origin and authentication checks on a locally bound WebSocket (CWE-346), a repeat of the local-agent WebSocket exposure pattern\n- **CVE:** CVE-2026-59723 (CVSS 8.8)\n- **Sources:** [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-59723), [Cline release](https://github.com/cline/cline/releases/tag/cli-v3.0.30)\n\n### 2026-07-08 - \"GhostApproval\" Symlink Flaws Defeat Human-in-the-Loop in Six AI Coding Assistants\n\n- **Target:** Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf\n- **Impact:** A malicious repository plants a symlink disguised as an innocuous file (for example `project_settings.json`) that points at `~/.ssh/authorized_keys` or a shell startup file. When the developer asks the agent to set up or edit the file, the agent writes attacker content through the symlink for passwordless SSH access or code execution, while the approval dialog displays the harmless presented path rather than the real target. Some tools write before approval or with no prompt at all\n- **Root Cause:** Agents follow symlinks with standard file operations but seek approval based on the shown path, not the resolved target (CWE-61 symlink following plus CWE-451 UI misrepresentation), so human approval is meaningless. Found by Wiz Research. Amazon (CVE-2026-12958, fixed in Language Server 1.69.0) and Cursor (CVE-2026-50549, fixed in 3.0) patched, Google fixed with a CVE pending, Augment and Windsurf were unpatched at disclosure, and Anthropic called it outside its threat model\n- **CVE:** CVE-2026-12958, CVE-2026-50549\n- **Sources:** [Wiz](https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants), [The Hacker News](https://thehackernews.com/2026/07/ghostapproval-symlink-flaws-could-let.html), [The Register](https://www.theregister.com/security/2026/07/08/bug-in-top-ai-coding-agents-shows-that-unix-era-security-headaches-never-really-die/)\n\n### 2026-07-08 - \"HalluSquatting\" Weaponizes AI Package-Name Hallucinations\n\n- **Target:** AI coding assistants Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and the OpenClaw family\n- **Impact:** Attackers register the fake package and repository names that models reliably invent, seed them with malicious code plus hidden prompt injection, and wait for an assistant to fetch the attacker version when a user asks for the \"real\" resource, chaining hallucination to code execution via the agent's terminal tool. Researchers measured an 85% consistency rate for the same incorrect repository names across phrasings and vendors and a 100% success rate for skill-install requests\n- **Root Cause:** Structural LLM hallucination of plausible but non-existent artifacts combined with agents that fetch and run model-named resources without verification. Found by the Ben Nassi group (Tel Aviv University) with Stav Cohen (Technion) and Ron Bitton (Intuit)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html)\n\n### 2026-07-08 - GitHub Copilot Guardrails Bypassed by Multi-Step Workflow Framing\n\n- **Target:** GitHub Copilot IDE agents in VS Code, backed by Claude Sonnet 4.6, Claude Haiku 4.5, Gemini 3.1 Pro, and Gemini 3.5 Flash\n- **Impact:** Harmful requests that Copilot refuses in direct chat succeed when decomposed into ordinary coding-workflow steps. Across 204 harmful prompts and four model backends, direct prompting produced only 8 of 816 unsafe completions, while the workflow-staged version produced 816 of 816, with usable harmful output typically after about six exchanges\n- **Root Cause:** Safety guardrails evaluate a single prompt in isolation, so reframing a harmful goal as a sequence of benign-looking IDE tasks slips past them. Found by the Alan Turing Institute (Abhishek Kumar, Carsten Maple)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/github-copilot-refuses-harmful-requests.html), [Help Net Security](https://www.helpnetsecurity.com/2026/07/09/github-coding-agent-jailbreak/), [The Register](https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i-cant-do-that-harmful-thing-unless-you-ask-me-in-code/)\n\n### 2026-07-08 - China's CNVDB Labels Claude Code a \"Backdoor\"; Alibaba Bans It\n\n- **Target:** Anthropic Claude Code, versions 2.1.91 (April 2) through 2.1.196 (June 29)\n- **Impact:** China's national vulnerability body alleged Claude Code contained a built-in monitoring mechanism that collected user location and identity data and sent it to external servers. Alibaba added Claude Code to its high-risk software list and barred employees from using it starting July 10, moving staff to in-house tools\n- **Root Cause:** Anthropic said the code was a March 2026 anti-abuse experiment that checked base URL, timezone, and hostname against reseller and Chinese-company lists to counter unauthorized reselling and model distillation, and that it was removed in version 2.1.198 (July 1). The dispute is over disclosure and intent rather than a formal CVE\n- **Sources:** [The Register](https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/5268371), [CNBC](https://www.cnbc.com/2026/07/08/china-anthropic-ai-claude-code-backdoor-security-threat.html), [TechCrunch](https://techcrunch.com/2026/07/04/alibaba-reportedly-bans-employees-from-using-claude-code/)\n\n### 2026-07-08 - Sygnia Documents Lone Attacker Breaching AWS in 72 Hours With Agentic AI\n\n- **Target:** An unnamed global enterprise's large AWS environment\n- **Impact:** A single financially motivated actor used AI-assisted, parallelized workflows to compromise a large AWS estate in about 72 hours, work that normally takes weeks, then attempted extortion. The attacker harvested secrets from S3, databases, Secrets Manager, and Parameter Store, established persistence via new access keys, IAM users, and reverse shells, exfiltrated RDS data, and staged reversible destructive moves (blocking S3 access, scaling containers to zero, writing deny ACLs, purging queues) for leverage; at one point four access keys from four accounts were used in a single second from one IP\n- **Root Cause:** LLM and agentic tooling lowered the barrier and accelerated recon, credential discovery, cloud enumeration, and pipeline abuse. Initial access came through an AWS key exposed by an internet-facing application. Investigated by Sygnia\n- **Sources:** [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/), [Dark Reading](https://www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment)\n\n### 2026-07-08 - Injective SDK npm Packages Backdoored to Steal Wallet Keys and Poison AI Agent Configs\n\n- **Target:** `@injectivelabs/sdk-ts` (about 50,000 weekly downloads) and 18 related packages\n- **Impact:** A compromised maintainer account pushed a backdoor that hooked `PrivateKey.fromMnemonic()` and `PrivateKey.fromHex()` to capture BIP-39 seed phrases and private keys the moment a wallet loaded, sending them to an attacker server; reporting noted the campaign also dropped persistent backdoor files into AI coding assistant configuration (a Claude Code SessionStart hook, Cursor rules, Gemini settings). The malicious version was live about 49 minutes and downloaded 310 times before a clean 1.20.23 was published, with no user funds reported lost\n- **Root Cause:** Maintainer account compromise plus automatic publishing propagated the tainted build across the scope within minutes; poisoning AI-assistant config files gives the malware persistence inside developer agents\n- **Sources:** [BleepingComputer](https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/), [The Hacker News](https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html), [StepSecurity](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys)\n\n### 2026-07-08 - ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge, First GenAI Android Malware\n\n- **Target:** Public AI agent skill repositories; Android users\n- **Impact:** ESET analyzed roughly 900,000 unique AI agent skills, flagging more than 25,000 as suspicious and over 3,000 as outright malicious, up from about 10,000 and 600 respectively as the scanned population grew from 60,000 to 900,000 between March and May 2026; capabilities included command execution, file and credential access, and obfuscation. The report also names PromptSpy, described as the first Android malware to use generative AI in its execution flow\n- **Root Cause:** Threat actors planting malicious skills in open marketplaces and repositories, and beginning to embed generative AI directly into malware\n- **Sources:** [Help Net Security](https://www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/), [ESET (GlobeNewswire)](https://www.globenewswire.com/news-release/2026/07/08/3323874/0/en/ESET-Threat-Report-AI-boosts-cyber-attackers-efficiency.html)\n\n### 2026-07-08 - LiteLLM MCP Authentication Bypass (CVE-2026-59822)\n\n- **Target:** LiteLLM (BerriAI) before 1.84.0\n- **Impact:** A fabricated `Authorization` header on the MCP Streamable HTTP endpoint triggers an OAuth2 passthrough fallback that replaces failed key validation with an empty auth object, letting an unauthenticated attacker reach MCP tooling without a valid key. Three sibling flaws the same day cover a Skills ZIP path traversal (CVE-2026-59820), an arbitrary file read via `/health/test_connection` (CVE-2026-59819), and unsandboxed code in Custom Code Guardrails (CVE-2026-59821)\n- **Root Cause:** Authentication fallback logic that fails open (CWE-287) in the MCP request path\n- **CVE:** CVE-2026-59822 (CVSS 8.8), CVE-2026-59820, CVE-2026-59819, CVE-2026-59821\n- **Sources:** [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-59822), [LiteLLM release](https://github.com/BerriAI/litellm/releases/tag/v1.84.0)\n\n### 2026-07-07 - \"GitLost\" Leaks Private Repositories via GitHub Agentic Workflows\n\n- **Target:** GitHub Agentic Workflows (public preview; agents running on Copilot, Claude, Gemini, or Codex inside GitHub Actions)\n- **Impact:** An unauthenticated attacker files a public GitHub issue containing hidden plain-English instructions; when the workflow triggers, the credentialed agent (which can read repositories the attacker cannot) follows them and posts private repository contents into a public comment. The proof of concept exfiltrated a private repo's README into a public comment, and prefixing the injection with \"Additionally\" bypassed GitHub's threat-detection guardrails\n- **Root Cause:** The agent cannot distinguish owner instructions from attacker-planted content in an untrusted issue (the \"lethal trifecta\" of private-data access, untrusted input, and a public output channel); GitHub describes it as an architectural limitation rather than a patchable bug. Found by Noma Security\n- **Sources:** [Noma Security](https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/), [The Hacker News](https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html), [SecurityWeek](https://www.securityweek.com/critical-vulnerability-exposes-github-agentic-workflows-to-prompt-injection/)\n\n### 2026-07-07 - Google Dialogflow CX \"Rogue Agent\" Cross-Agent Hijack\n\n- **Target:** Google Dialogflow CX agents using Code Block Playbooks with custom Python\n- **Impact:** An attacker with `dialogflow.playbooks.update` permission on one Code Block-enabled agent could overwrite `code_execution_env.py` in a shared, customer-invisible Cloud Run runtime, running injected code for every agent in the same Google Cloud project to read live conversations, steal user data, and inject phishing responses\n- **Root Cause:** A writable setup file in a shared runtime with no isolation between agents, plus unrestricted outbound access and exposed metadata. Found by Varonis; reported November 2025, initially fixed April 2026 and fully resolved June 2026, with no evidence of in-the-wild abuse and no CVE\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.html), [Axios](https://www.axios.com/2026/07/07/varonis-google-ai-agent-chatbot-security), [Dark Reading](https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft)\n\n### 2026-07-07 - \"WriteOut\" Cross-Tenant Account Takeover in Writer AI\n\n- **Target:** Writer enterprise generative AI platform, live agent preview feature\n- **Impact:** A logged-in user who clicked a shared agent preview link could have their account hijacked across organizational tenants, exposing private chats, documents, agent configurations, private models, connectors, and LLM credentials, with potential admin control\n- **Root Cause:** Writer served agent previews from the same origin as the main app, so the browser auto-attached the user's session cookie and the proxy forwarded it into the attacker-controlled sandbox, breaking tenant isolation. Found by SAND Security; Writer moved previews to an isolated origin and stopped forwarding the session cookie, fixing it within 24 hours, with no customer data compromised\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html), [SAND Security](https://www.sandsecurity.ai/blog/writeout-writer-ai-cross-tenant)\n\n### 2026-07-07 - CISA Adds Langflow IDOR (CVE-2026-55255) to KEV, First AI Agent Platform in the Catalog\n\n- **Target:** Langflow before 1.9.1 (guidance updated to 1.9.2)\n- **Impact:** An insecure direct object reference in `/api/v1/responses` lets an authenticated attacker execute any flow belonging to another user by supplying the victim's flow ID, exposing embedded LLM provider keys, cloud credentials, and database secrets. Sysdig observed a lone operator chaining reconnaissance, this IDOR, and a loop of the Langflow RCE CVE-2026-33017 between June 22 and 25, 2026 to harvest secrets and stage second-stage implants. CISA added it to the Known Exploited Vulnerabilities catalog on July 7 with a July 10 federal deadline, the first AI agent orchestration platform to enter the catalog\n- **Root Cause:** Authorization bypass through a user-controlled key (CWE-639); flow lookups query by UUID with no ownership check\n- **CVE:** CVE-2026-55255 (NVD CVSS 8.4; vendor rates 9.9)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html), [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/), [Help Net Security](https://www.helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited/)\n\n### 2026-07-07 - Google Gemini Live API RCE via Unconstrained Ephemeral Tokens\n\n- **Target:** Browser-based applications using the Gemini Live API for voice sessions\n- **Impact:** Misconfigured ephemeral tokens let a client override the system prompt and tool definitions and trigger code execution; a proof of concept ran `os.uname()` and returned a nonce-based SHA-256 to prove genuine execution. The weakness traces back to Google's own reference implementation\n- **Root Cause:** Every setup-frame field is optional, so any parameter not locked server-side (via `live_connect_constraints`) stays client-controllable. Reported by researcher Alvin Ferdiansyah\n- **Sources:** [GBHackers](https://gbhackers.com/google-gemini-live-api-flaw/), [Cybersecurity News](https://cybersecuritynews.com/gemini-live-voice-session-flaw/)\n\n### 2026-07-07 - mem0 Unauthenticated Memory Access and Key Disclosure (CVE-2026-59705, CVE-2026-59706)\n\n- **Target:** mem0 (mem0ai) OpenMemory API\n- **Impact:** OpenMemory API routers were registered with no authentication, letting an unauthenticated attacker read, write, or delete arbitrary user memories and force a global pause for denial of service (CVE-2026-59705); a companion flaw exposes LLM API keys in plaintext through the config API and allows SSRF via the `ollama_base_url` value (CVE-2026-59706)\n- **Root Cause:** Missing authentication middleware on agent memory endpoints (CWE-306), a direct memory-poisoning and credential-theft path against a widely used agent memory store\n- **CVE:** CVE-2026-59705 (CVSS 9.3), CVE-2026-59706 (CVSS 9.2)\n- **Sources:** [NVD CVE-2026-59705](https://nvd.nist.gov/vuln/detail/CVE-2026-59705), [NVD CVE-2026-59706](https://nvd.nist.gov/vuln/detail/CVE-2026-59706)\n\n### 2026-07-07 - DigiCert AI Trust Outlook: 78% of Enterprises Report AI Security Incidents\n\n- **Target:** Enterprise AI deployments (survey of 1,001 IT and security decision-makers in the US, UK, and Australia, conducted May 2026)\n- **Impact:** 78% of organizations said they experienced AI-related incidents or identified AI-related vulnerabilities, which coverage attributes largely to unauthorized or misconfigured AI agents. Nearly half lack centralized visibility into their AI systems and 47% cannot fully trace AI decisions back to models and source data, even as 75% deployed four or more AI-powered systems in the prior six months\n- **Root Cause:** AI adoption outrunning governance, identity, and visibility controls\n- **Sources:** [DigiCert (GlobeNewswire)](https://www.globenewswire.com/news-release/2026/07/07/3323253/0/en/latest-digicert-research-shows-ai-security-risks-already-hitting-enterprises-with-78-reporting-incidents.html), [The Register](https://www.theregister.com/security/2026/07/07/enterprise-ai-still-smarting-from-leaping-before-looking/5267353), [SD Times](https://sdtimes.com/ai-governance/survey-reveals-78-of-enterprises-are-reporting-ai-related-security-incidents/)\n\n### 2026-07-07 - Trend Micro \"Stars Don't Save You\" MCP Ecosystem Study\n\n- **Target:** 9,695 MCP servers indexed across GitHub, Glama, Lobehub, and PulseMCP\n- **Impact:** 5,832 servers carried at least one weakness and 2,259 had confirmed exploitable vulnerabilities across 4,982 distinct issues, including 2,054 with no authentication, 880 arbitrary file access, 490 denial of service, 476 command injection, 422 SSRF, 211 SQL injection, and 185 prompt injection. The study found no correlation between GitHub stars or verification badges and actual security\n- **Root Cause:** An immature MCP ecosystem where popularity signals do not track security and many servers ship without authentication or input validation\n- **Sources:** [Trend AI Security](https://www.trendaisecurity.com/en-us/resources-insights/research/stars-dont-save-you-popularity-is-not-security-in-the-mcp-ecosystem), [Cyberpress](https://cyberpress.org/4982-security-issues-expose-2259-public-mcp-servers-to-ai-agent-attacks/), [GBHackers](https://gbhackers.com/thousands-of-mcp-servers-found-vulnerable/)\n\n### 2026-07-06 - \"SkillCloak\" Repacks Malicious AI Agent Skills to Evade Scanners\n\n- **Target:** AI agent skill marketplaces and scanners; cloaked skills tested against Claude Code and OpenAI Codex\n- **Impact:** SkillCloak preserves a payload's malicious behavior while rewriting its visible structure, using structural obfuscation and self-extracting packing that hides components in scanner-skipped directories such as `.git` and restores them at runtime. Across 8 scanners and 1,613 real malicious ClawHub skills, self-extracting packing evaded every scanner more than 90% of the time (most above 99%) and dropped the best static scanner from about 99% to 10% detection, while cloaked skills still ran under production agents with no measurable loss of function; the authors' runtime detector SkillDetonate caught 97% of synthetic and 87% of real-world cases\n- **Root Cause:** Static scanners inspect skills at submission time, but malicious behavior manifests at runtime. Found by the Hong Kong University of Science and Technology\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html), [Help Net Security](https://www.helpnetsecurity.com/2026/07/09/malicious-ai-agent-skills-scan/), [arXiv](https://arxiv.org/abs/2607.02357)\n\n### 2026-07-06 - Summer.fi \"Keeper AI Agents\" Exploit Drains About $6M\n\n- **Target:** Summer.fi (Lazy Summer Protocol) DeFi automation\n- **Impact:** An exploit drained roughly $6 million, with the attack path traversing the protocol's automated \"Keeper AI Agents\" that handle rebalancing; commentators framed it as AI automation now sitting above smart-contract risk. It was one of several DeFi incidents in the week (a BonkDAO governance drain and a Bonzo Lend oracle exploit) totaling around $35 million\n- **Root Cause:** Automated agent-driven protocol actions layered on top of smart-contract exposure, expanding the blast radius of the underlying exploit\n- **Sources:** [CryptoSlate](https://cryptoslate.com/summer-fi-exploit-shows-ai-automation-now-sits-above-defi-smart-contract-risk/), [Crypto Times](https://www.cryptotimes.io/2026/07/12/crypto-loses-35m-in-a-week-bonkdao-bonzo-lend-summer-fi-hacked/)\n\n### 2026-07-06 - OpenAI Codex Desktop Zero-Click Data Exfiltration (CVE-2026-14898)\n\n- **Target:** OpenAI Codex desktop app for macOS before 26.527.31326\n- **Impact:** The app renders remote Markdown images returned by the model, so an indirect prompt injection can make the model build a remote image URL containing sensitive data that is fetched automatically with no user click, leaking it to an attacker server\n- **Root Cause:** Auto-fetching remote images from untrusted model output (CWE-200), the same image-based exfiltration pattern seen in other assistants\n- **CVE:** CVE-2026-14898 (CVSS 6.5)\n- **Sources:** [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-14898), [OpenAI Codex](https://openai.com/codex/)\n\n### 2026-07-02 - Zscaler Documents In-the-Wild Indirect Prompt Injection Targeting Autonomous AI Agents\n\n- **Target:** Autonomous web-browsing AI agents; two live malicious-website campaigns observed by Zscaler ThreatLabz\n- **Impact:** One campaign used SEO poisoning plus hidden CSS and JSON-LD to impersonate a fake Python package \"requests-secure-v2\" and push agents to pay a bogus \"$3.00 developer API license\" plus about 0.0012 ETH to an attacker wallet; a second typosquatted DeBank via \"debank[.]auction.\" In Zscaler's validation across 26 models, four (Llama 3.3 70B, Llama 3.2 90B Vision, Gemini 3 Flash, Gemini 2.5 Pro) executed the fraudulent payment and two misclassified the fake site as legitimate\n- **Root Cause:** Indirect prompt injection: agents ingest and act on hidden instructions embedded in retrieved web content with no boundary between data and instructions\n- **Sources:** [Zscaler ThreatLabz](https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents), [Cybersecurity News](https://cybersecuritynews.com/hackers-abuse-seo-poisoning-and-hidden-html/)\n\n### 2026-07-02 - fast-mcp-telegram MCP Server Authentication Bypass (CVE-2026-52830)\n\n- **Target:** fast-mcp-telegram MCP server (PyPI), versions before 0.19.1\n- **Impact:** A remote, unauthenticated attacker bypasses authentication with a crafted Bearer token such as `../fast-mcp-telegram/telegram` to authenticate as the default legacy session, reaching the MCP tools and the connected Telegram account data across tenant boundaries\n- **Root Cause:** The Bearer token is joined directly into a session-file path with no normalization; the server rejects the literal token \"telegram\" but not path separators (CWE-22 path traversal plus CWE-287 improper authentication)\n- **CVE:** CVE-2026-52830 (CVSS 9.4)\n- **Sources:** [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-52830), [GitLab Advisory](https://advisories.gitlab.com/pypi/fast-mcp-telegram/CVE-2026-52830/)\n\n### 2026-07-01 - \"JADEPUFFER\" First Documented End-to-End Agentic Ransomware\n\n- **Target:** An internet-facing Langflow instance used for initial access, then a production database environment (MySQL and the Alibaba Nacos configuration service)\n- **Impact:** Sysdig documented what it calls the first extortion operation run end to end by an autonomous LLM agent: recon, credential theft, lateral movement, privilege escalation, and persistence, culminating in the encryption of 1,342 Nacos service-configuration items before the originals were deleted. The agent self-narrated, adapted in real time (a failed login diagnosed and fixed in 31 seconds), and swept for LLM API keys and cloud credentials; the encryption key was generated randomly and never stored, making recovery impossible\n- **Root Cause:** Initial access via the older Langflow unauthenticated code-execution flaw CVE-2025-3248, with Nacos reached through auth-bypass CVE-2021-29441; the novelty is the fully agent-driven operation rather than a new vulnerability\n- **CVE:** CVE-2025-3248, CVE-2021-29441 (exploited, not newly disclosed)\n- **Sources:** [Sysdig](https://sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion), [The Register](https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/), [BleepingComputer](https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/)\n\n### 2026-07-01 - Cursor \"DuneSlide\" Zero-Click Prompt-Injection RCE (CVE-2026-50548, CVE-2026-50549)\n\n- **Target:** Cursor AI code editor before 3.0 (fix shipped in Cursor 3.0, released April 2, 2026)\n- **Impact:** A single innocuous prompt that ingests attacker-controlled content from an MCP server or web-search result can escape the terminal sandbox and reach OS-level remote code execution with no user interaction, giving full compromise of the host machine and connected SaaS workspaces\n- **Root Cause:** Two chained flaws let injected instructions overwrite the `cursorsandbox` enforcer binary: CVE-2026-50548 trusts the agent-chosen working directory so a system path grants out-of-scope write permission, and CVE-2026-50549 is a symlink canonicalization check that fails open when path resolution fails. Reported by Cato AI Labs (Itay Ravia) on February 19, 2026; CVEs assigned June 5 and detailed publicly on July 1, 2026\n- **CVE:** CVE-2026-50548, CVE-2026-50549 (both CVSS 9.8)\n- **Sources:** [Cato Networks](https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/), [The Hacker News](https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html), [SecurityWeek](https://www.securityweek.com/critical-cursor-ai-ide-flaws-could-lead-to-os-level-remote-code-execution/)\n\n### 2026-07-01 - Check Point Demonstrates LLM-Generated Browser-Native Ransomware\n\n- **Target:** Chromium-based browsers (Chrome, Edge) on Windows, macOS, Linux, ChromeOS, and Android; proof-of-concept technique generated by prompting DeepSeek\n- **Impact:** A fake image-enhancement page uses the browser File System Access API (`showDirectoryPicker`) to read, exfiltrate, and encrypt a victim's local files with no native payload, app install, browser exploit, or root access. iOS and Safari are unaffected because the API is not exposed there\n- **Root Cause:** A large language model connected an unrealistic \"browser malware\" idea to a legitimate, sanctioned browser permission API, producing a practical social-engineering abuse path rather than exploiting a browser vulnerability\n- **Sources:** [Check Point Research](https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallucinations-to-a-practical-attack-technique/), [The Hacker News](https://thehackernews.com/2026/07/ai-generated-browser-ransomware-abuses.html)\n\n### 2026-07-01 - Apify Actors MCP Server Token Exfiltration (CVE-2026-50143)\n\n- **Target:** `@apify/actors-mcp-server` (npm), all versions before 0.10.11\n- **Impact:** A malicious Apify Actor with a crafted path can exfiltrate the victim's Apify API token; the MCP client automatically attaches the `Authorization: Bearer \u003cAPIFY_TOKEN\u003e` header to every outbound connection, so redirecting the client to an attacker host leaks the credential\n- **Root Cause:** Unsafe URL construction that concatenates a trusted base URL with an attacker-controlled `webServerMcpPath` value taken from an Actor definition returned by the Apify API (CWE-918 server-side request forgery)\n- **CVE:** CVE-2026-50143 (CVSS 8.1)\n- **Sources:** [GitLab Advisory](https://advisories.gitlab.com/npm/@apify/actors-mcp-server/CVE-2026-50143/)\n\n### 2026-06-30 - \"GuardFall\" Shell-Injection Bypass in Open-Source AI Coding Agents\n\n- **Target:** 10 of 11 tested open-source AI coding and computer-use agents, including opencode, Goose, Cline, Roo-Code, Aider, Plandex, Open Interpreter, OpenHands, SWE-agent, and a NousResearch Hermes agent; only Continue mitigated it\n- **Impact:** Pattern-based command guards can be bypassed, so a poisoned README, MCP server, or Makefile can drive an agent into running destructive shell commands with the operator's full privileges, including wiping files or exfiltrating SSH keys and cloud credentials. Disclosed as lab research with no in-the-wild exploitation reported\n- **Root Cause:** Guards inspect the raw command string, but Bash performs quote removal, `$IFS` and parameter expansion, and command substitution before execution, so obfuscated commands slip past denylists; a decades-old shell-quoting bypass applied to AI agents. Found by Adversa AI (Omer Ben Simon)\n- **Sources:** [Adversa AI](https://adversa.ai/blog/opensource-ai-coding-agents-shell-injection-vulnerability/), [The Hacker News](https://thehackernews.com/2026/06/guardfall-exposes-open-source-ai-coding.html), [SC Media](https://www.scworld.com/brief/shell-injection-flaw-found-in-10-of-11-open-source-ai-agents)\n\n### 2026-06-30 - Palo Alto Unit 42 \"Phantom Squatting\" - AI-Hallucinated Domains as an Attack Surface\n\n- **Target:** 913 global brands analyzed; AI agents and users that trust LLM-generated URLs\n- **Impact:** From 685,339 adversarial prompts, Unit 42 collected 2.1 million unique URLs and identified roughly 250,000 unregistered \"phantom\" domains that adversaries can register, plus 13,229 URLs already flagged malicious. Documented real abuse includes a \"Montana Empire\" phishing kit on a hallucinated postal-service domain (registered about 23 days after the model predicted it) and a malicious Android APK hosted on another phantom domain\n- **Root Cause:** Structural LLM hallucination of non-existent but plausible domains (\"zero-reputation bypass\"); described as inherently hard to patch because it stems from model behavior rather than a software flaw\n- **Sources:** [Palo Alto Unit 42](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/), [Check Point Research](https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2/)\n\n### 2026-06-30 - Anthropic \"buffa\" Rust protobuf Memory-Amplification DoS (CVE-2026-55407)\n\n- **Target:** buffa, Anthropic's Rust protobuf library, versions before 0.8.0\n- **Impact:** An attacker sending crafted protobuf wire data to any service that decodes untrusted input with the default `preserve_unknown_fields=true` can force unbounded heap allocation; a nested-group path amplifies roughly 22x, so a 64 MiB message triggers about 1.4 GB of allocation and out-of-memory crashes\n- **Root Cause:** The `decode_unknown_field` path allocates memory proportional to attacker-controlled data with no per-message field-count limit; the 0.8.0 fix caps unknown fields (default 1 million) and bounds overhead. Found by Endor Labs' AI SAST engine (Peyton Kennedy)\n- **CVE:** CVE-2026-55407 (CVSS 6.3)\n- **Sources:** [Endor Labs](https://www.endorlabs.com/learn/endor-labs-ai-sast-finds-zero-day-cve-2026-55407-buffa)\n\n### 2026-06-26 - Amazon Q Developer Silent MCP Config Auto-Load (CVE-2026-12957, CVE-2026-12958)\n\n- **Target:** Language Servers for AWS before 1.69.0; Amazon Q Developer for VS Code before 2.20, JetBrains before 4.3, Eclipse before 2.7.4; AWS Toolkit with Amazon Q for Visual Studio before 1.94.0.0\n- **Impact:** Opening a malicious repository silently executes commands and steals credentials, including AWS access keys, session tokens, cloud CLI tokens, API secrets, and SSH agent sockets, because spawned processes inherit the full developer environment\n- **Root Cause:** The extension auto-loaded MCP server configurations from `.amazonq/mcp.json` workspace files with no user consent or workspace-trust verification (CVE-2026-12957, improper trust boundary), plus missing symlink validation (CVE-2026-12958); found by Wiz Research (Maor Dokhanian) on April 20, 2026 and patched May 12, 2026\n- **CVE:** CVE-2026-12957, CVE-2026-12958\n- **Sources:** [Cybersecurity News](https://cybersecuritynews.com/amazon-q-vulnerability/), [AWS Security Blog (ICYMI May 2026)](https://aws.amazon.com/blogs/security/icymi-may-2026-aws-security/)\n\n### 2026-06-23 - Dify \"DifyTap\" Cross-Tenant Data Exposure (CVE-2026-41947 to CVE-2026-41950)\n\n- **Target:** Dify (LangGenius) open-source LLM app platform, fixed in 1.14.2\n- **Impact:** Four flaws, two critical and two unauthenticated. The tracing subsystem can be redirected to an attacker endpoint to persistently exfiltrate all messages and responses from any accessible application (CVE-2026-41947); the Plugin Daemon allows unauthenticated access to arbitrary internal API endpoints via path traversal (CVE-2026-41948); console users and chatbots can read other organizations' documents and attached files (CVE-2026-41949, CVE-2026-41950)\n- **Root Cause:** Missing tenant-identity validation and absent authentication on internal file and tracing endpoints; the platform also shipped a vulnerable PDFium binary for 18+ months, and container scanners missed the issues due to Dify's unpackaged code layout\n- **CVE:** CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, CVE-2026-41950\n- **Sources:** [SC Media](https://www.scworld.com/brief/four-vulnerabilities-in-dify-expose-cross-tenant-data), [UVcyber Threat Advisory](https://www.uvcyber.com/resources/reports/threat-advisory-difytap-vulnerabilities)\n\n### 2026-06-22 - vLLM OpenAI-Compatible API Authentication Bypass (CVE-2026-48746)\n\n- **Target:** vLLM OpenAI-compatible API server, versions 0.3.0 through 0.21.x (fixed in 0.22.0)\n- **Impact:** A remote attacker bypasses API-key authentication and reaches protected inference endpoints without a valid `VLLM_API_KEY` or `--api-key`\n- **Root Cause:** `AuthenticationMiddleware.__call__` reconstructed the request path with `URL(scope=scope).path`, which trusts the unsanitized `Host` header; a crafted `Host: localhost/v1/models?` manipulates the path so the `/v1` auth check fails open. The fix uses `scope[\"path\"]` directly\n- **CVE:** CVE-2026-48746 (CVSS 9.1)\n- **Sources:** [Miggo Vulnerability Database](https://www.miggo.io/vulnerability-database/cve/CVE-2026-48746), [OpenCVE](https://app.opencve.io/cve/?vendor=vllm-project\u0026product=vllm)\n\n### 2026-06-18 - Microsoft AutoGen Studio \"AutoJack\" Drive-By Code Execution\n\n- **Target:** Microsoft AutoGen Studio built from the GitHub main branch after the MCP plugin was added and before commit b047730; published PyPI releases, including autogenstudio 0.4.2.2, were not affected\n- **Impact:** A malicious webpage tricks a localhost AutoGen Studio agent into executing arbitrary PowerShell, Bash, or executables with the developer's privileges; Microsoft demonstrated launching Calculator from a visited page\n- **Root Cause:** Three chained weaknesses: the MCP WebSocket trusted localhost connections, the auth middleware excluded `/api/mcp/*` routes, and the WebSocket accepted a base64 `server_params` value from the URL and passed it to process-launch code\n- **Sources:** [BleepingComputer](https://www.bleepingcomputer.com/news/security/microsoft-fixes-autogen-studio-flaw-that-enabled-code-execution/), [Threat Modeling](https://threat-modeling.com/microsoft-autogen-studio-code-execution-june-2026/)\n\n### 2026-06-17 - Mastra AI npm Scope Compromise (Sapphire Sleet / UNC1069)\n\n- **Target:** 144+ packages across the `mastra` and `@mastra` npm scope; `@mastra/core` draws more than 918,000 weekly downloads\n- **Impact:** The entire scope was backdoored in an 88-minute automated campaign; a malicious `easy-day-js` typosquat of dayjs ran a `postinstall` dropper that disabled TLS verification, contacted a C2, and downloaded a detached cross-platform information stealer that harvested browser history and 160+ cryptocurrency wallet extensions before self-deleting\n- **Root Cause:** Takeover of a dormant former-contributor npm account (`ehindero`) that still held publish rights, reached via a malicious LinkedIn link to an active employee; Microsoft attributed it to North Korean actor Sapphire Sleet (UNC1069), the same actor behind the earlier Axios compromise\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html), [Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/), [Snyk](https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/)\n\n### 2026-06-15 - Microsoft 365 Copilot \"SearchLeak\" One-Click Data Theft (CVE-2026-42824)\n\n- **Target:** Microsoft 365 Copilot Enterprise (Copilot Search)\n- **Impact:** A single malicious link click could steal emails, calendar details, indexed SharePoint and OneDrive files, one-time and MFA codes, and password-reset links with no authentication; Varonis demonstrated a proof of concept, with no in-the-wild exploitation observed. Microsoft mitigated server-side\n- **Root Cause:** Three chained flaws: parameter-to-prompt injection through the search `q` parameter, a race condition where streamed content rendered before sanitization, and a Content Security Policy allowlist bypass through Bing's image-fetch endpoint\n- **CVE:** CVE-2026-42824 (Microsoft 6.5, NVD 7.5)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html), [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-attack-turned-microsoft-365-copilot-into-1-click-data-theft-tool/), [Varonis](https://www.varonis.com/blog/searchleak)\n\n### 2026-06-08 - Langflow Path Traversal RCE Exploited in the Wild (CVE-2026-5027)\n\n- **Target:** Langflow before 1.9.0; roughly 7,000 instances exposed on the public internet (Censys)\n- **Impact:** Unauthenticated arbitrary file write leading to remote code execution, for example dropping a cron job; default auto-login means a single unauthenticated request reaches the vulnerable endpoint. After disclosure by Tenable and a 1.9.0 patch, attackers weaponized the flaw and exploitation was observed in June 2026\n- **Root Cause:** `POST /api/v2/files` does not sanitize the multipart `filename` parameter, allowing `../` traversal to write files anywhere on the filesystem\n- **CVE:** CVE-2026-5027 (CVSS 8.8)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html), [Orca Security](https://orca.security/resources/blog/cve-2026-5027-langflow-path-traversal-rce/), [SecurityWeek](https://www.securityweek.com/critical-langflow-vulnerability-exploited-hours-after-public-disclosure/)\n\n### 2026-06-05 - Hades PyPI Worm Wave (Shai-Hulud / Miasma Lineage)\n\n- **Target:** 19 PyPI packages across 37 malicious wheel artifacts, with a secondary cluster targeting computational-biology and MCP developers (IBM X-Force)\n- **Impact:** A `*-setup.pth` file runs the payload at Python interpreter startup with no import required; a Bun-based JavaScript stealer harvests credentials for GitHub, npm, PyPI, JFrog, CircleCI, Anthropic, AWS, GCP, Azure, and Kubernetes, plus SSH keys and Vault tokens. Notably, the malware embeds a plain-text prompt injection that tries to trick LLM-based package-analysis tools into rating it safe\n- **Root Cause:** `.pth` startup-hook execution combined with the Shai-Hulud and Miasma worm lineage; GitHub repo descriptions carried the marker \"Hades - The End for the Damned\"\n- **Sources:** [Socket](https://socket.dev/blog/shai-hulud-descends-to-hades-miasma-pypi-wave), [The Hacker News](https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html), [Dark Reading](https://www.darkreading.com/application-security/hades-campaign-pypi-shai-hulud)\n\n### 2026-06-05 - Claude Code GitHub Action Prompt-Injection Secret Exfiltration\n\n- **Target:** Claude Code GitHub Action before 2.1.128\n- **Impact:** Prompt injection hidden in GitHub issues, pull requests, or comments could steer the agent into reading unsanitized environment data through `/proc/self/environ` and exfiltrating CI/CD secrets, API keys, and cloud credentials through issue comments, workflow logs, web requests, or shell commands\n- **Root Cause:** The agent processed untrusted GitHub content in the same runtime that held privileged secrets; disclosed by Microsoft researchers through HackerOne on April 29, 2026 and patched in 2.1.128 on May 5, 2026\n- **Sources:** [Decrypt](https://decrypt.co/370238/claude-code-vulnerability-attackers-steal-credentials-github-microsoft), [Cloud Security Alliance Lab](https://labs.cloudsecurityalliance.org/research/csa-research-note-claude-code-github-action-prompt-injection/)\n\n### 2026-06-03 - node-gyp \"Phantom Gyp\" Self-Propagating npm Worm (Miasma)\n\n- **Target:** 57 npm packages across hundreds of malicious versions; the largest AI target was `@vapi-ai/server-sdk` (Vapi.ai voice-AI SDK, ~86,500 weekly downloads), with poisoned versions 0.11.1, 0.11.2, 1.2.1, and 1.2.2\n- **Impact:** A weaponized `binding.gyp` makes node-gyp execute attacker code during the `npm install` configuration phase, bypassing pre/postinstall monitoring; it harvests npm, GitHub, AWS, GCP, Azure, Vault, and Kubernetes credentials, injects GitHub Actions workflows for persistence, and self-propagates\n- **Root Cause:** Novel abuse of GYP command-expansion syntax in `binding.gyp` build hooks; a descendant of the Shai-Hulud and Miasma worm families\n- **Sources:** [Snyk](https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/), [StepSecurity](https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm)\n\n### 2026-06-01 - Red Hat @redhat-cloud-services npm \"Miasma\" Worm\n\n- **Target:** At least 32 package releases under the `@redhat-cloud-services` npm namespace (averaging ~80,000 weekly downloads), originating in the RedHatInsights/javascript-clients CI/CD pipeline\n- **Impact:** A `preinstall` hook ran an obfuscated `index.js` dropper that steals GitHub tokens, SSH keys, and GCP and Azure cloud identities on developer machines, scrapes GitHub Actions runner memory in CI, and republishes poisoned packages with valid SLSA provenance attestations\n- **Root Cause:** A compromised Red Hat employee account injected malicious GitHub Actions workflows that requested an OIDC token via `id-token: write` and abused npm trusted publishing; part of the Shai-Hulud and Miasma lineage. Tracked as Red Hat RHSB-2026-006\n- **Sources:** [Wiz](https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages), [Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/), [Red Hat](https://access.redhat.com/security/vulnerabilities/RHSB-2026-006)\n\n### 2026-05-28 - Nx Console Malicious VS Code Extension Leads to GitHub Repository Breach\n\n- **Target:** Poisoned Nx Console VS Code extension (malicious build delivered via auto-update) used to compromise a GitHub employee device\n- **Impact:** Unauthorized access to and exfiltration of internal GitHub source-code repositories after the trojanized IDE extension ran on the victim's machine\n- **Root Cause:** A prior Nx developer-system compromise let attackers push a trojanized extension build through the marketplace auto-update channel, abusing the trust developers place in recommended IDE extensions\n- **Sources:** [CISA Alert](https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories), [BleepingComputer](https://www.bleepingcomputer.com/news/security/vscode-ide-forks-expose-users-to-recommended-extension-attacks/)\n\n### 2026-05-25 - \"Megalodon\" Mass GitHub Actions Secret Exfiltration\n\n- **Target:** 5,561 distinct public GitHub repositories hit by 5,718 malicious commits, surfaced through trojanized Tiledesk npm versions\n- **Impact:** Injected GitHub Actions workflows harvested CI environment variables, AWS, GCP, and Azure credentials, SSH keys, Docker and Kubernetes configs, and GitLab and GitHub tokens, deployed across a six-hour window on May 18, 2026\n- **Root Cause:** Malicious CI workflows injected across thousands of repositories; the same npm account that shipped clean Tiledesk versions unknowingly published poisoned ones after its GitHub repository was compromised. Researched by SafeDep with additional analysis from OX Security\n- **Sources:** [SecurityWeek](https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/), [StepSecurity](https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories)\n\n### 2026-05-20 - NVIDIA Triton Inference Server Authentication Bypass (CVE-2026-24207)\n\n- **Target:** NVIDIA Triton Inference Server on Linux, all releases prior to r26.03\n- **Impact:** A critical unauthenticated authentication bypass can lead to code execution, privilege escalation, data tampering, denial of service, or information disclosure, alongside seven additional flaws including path traversal, integer overflow, and DALI-backend issues\n- **Root Cause:** Authentication bypass (CWE-288) plus memory-safety and integer-overflow defects in the model-serving stack\n- **CVE:** CVE-2026-24207 (CVSS 9.8); also CVE-2026-24206, -24208, -24209, -24210, -24213, -24214, -24215\n- **Sources:** [NVIDIA Security Bulletin](https://nvidia.custhelp.com/app/answers/detail/a_id/5828/~/security-bulletin:-nvidia-triton-inference-server---may-2026), [Security Online](https://securityonline.info/nvidia-triton-inference-server-vulnerability-cve-2026-24207-authentication-bypass/)\n\n### 2026-05-18 - actions-cool GitHub Actions Tag Hijack (Mini Shai-Hulud)\n\n- **Target:** `actions-cool/issues-helper` (all 53 tags) and `actions-cool/maintain-one-comment` (15 tags), retargeted to a single imposter commit\n- **Impact:** A Bun-based payload reads decrypted secrets directly from the `Runner.Worker` process memory inside GitHub Actions and exfiltrates CI/CD credentials from every workflow that pinned the actions by tag\n- **Root Cause:** Repository or maintainer compromise plus mutable-tag retargeting, attributed to the TeamPCP Mini Shai-Hulud campaign\n- **Sources:** [StepSecurity](https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials), [The Hacker News](https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html)\n\n### 2026-05-15 - PraisonAI Auth-Disabled API Server (CVE-2026-44338)\n\n- **Target:** PraisonAI legacy Flask API server, before 4.6.34\n- **Impact:** Unauthenticated attackers enumerate configured agents via `GET /agents`, trigger workflows via `POST /chat`, extract sensitive output, and exhaust costly model quotas; exploited within hours of disclosure\n- **Root Cause:** Hardcoded insecure defaults (`AUTH_ENABLED = False`, `AUTH_TOKEN = None`) with the server bound to `0.0.0.0:8080` and a `check_auth()` that fails open when auth is disabled\n- **CVE:** CVE-2026-44338\n- **Sources:** [Cybersecurity News](https://cybersecuritynews.com/praisonai-vulnerability-exploited/)\n\n### 2026-05-14 - OpenAI Internal Source Code and Certificate Theft via TanStack Worm\n\n- **Target:** OpenAI internal source-code repositories and code-signing certificates\n- **Impact:** Attackers stole limited credential material and digital certificates used to sign OpenAI products from a limited subset of internal repositories after two employee devices were infected; OpenAI said no user data, production systems, or intellectual property were compromised and rotated affected certificates, forcing a macOS app update\n- **Root Cause:** The compromise of the open-source TanStack library, where attackers published 84 malicious versions in a roughly six-minute window (part of the Mini Shai-Hulud worm), infected the developer machines that reached OpenAI's repositories\n- **Sources:** [TechCrunch](https://techcrunch.com/2026/05/14/openai-says-hackers-stole-some-data-after-latest-code-security-issue/), [The Hacker News (Mini Shai-Hulud)](https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html)\n\n### 2026-05-12 - Claude Code Deeplink RCE\n\n- **Target:** Claude Code before 2.1.118\n- **Impact:** A crafted `claude-cli://` deeplink injects `--settings={...}` (including a `SessionStart` hooks payload) through the `--prefill` value, so one click runs arbitrary shell commands; pointing the deeplink's `repo` parameter at an already-trusted local repository suppressed all warning prompts for a silent compromise\n- **Root Cause:** `eagerParseCliFlag` in `main.tsx` used `startsWith` across the whole argv array without tracking whether a `--settings=` string was a real flag or the value of another flag, letting flags be smuggled inside values. Researcher: Joern Chen (joernchen, 0day.click)\n- **Sources:** [0day.click](https://0day.click/recipe/2026-05-12-cc-rce/), [GBHackers](https://gbhackers.com/claude-code-vulnerability/), [Cybersecurity News](https://cybersecuritynews.com/claude-code-rce-flaw/)\n\n### 2026-05-12 - Cline AI Agent Unauthenticated WebSocket RCE (CVE-2026-44211)\n\n- **Target:** Cline AI coding agent (the bundled Kanban npm server) on macOS, Linux, and Windows; no patched version at disclosure\n- **Impact:** A malicious webpage can reach Cline's background local WebSocket server on port 3484, leak filesystem paths, git branch details, task titles, and live agent chat messages, and execute arbitrary code on the developer's machine\n- **Root Cause:** The local WebSocket server started with no authentication and no Origin-header validation, and browsers do not restrict cross-origin WebSocket connections to localhost. Documented by Oasis Security and researcher TheRealSpencer\n- **CVE:** CVE-2026-44211 (CVSS 9.7)\n- **Sources:** [Cybersecurity News](https://cybersecuritynews.com/cline-ai-agent-vulnerability/), [Oasis Security](https://www.oasis.security/blog/)\n\n### 2026-05-12 - GitHub Copilot and VS Code Security-Feature Bypass (CVE-2026-41109)\n\n- **Target:** GitHub Copilot extension before v1.43.20260512 and Visual Studio Code up to 1.96.x (fixed in VS Code 1.97.0)\n- **Impact:** A low-privileged local attacker can bypass Copilot's user-consent prompts and content filters, inject malicious code suggestions, silently disable telemetry consent, and leak environment variables and API keys through suggestion logging\n- **Root Cause:** Improper validation of inter-process communication between the Copilot extension and the VS Code core when the workspace was marked trusted; the flaw is in the integration layer, not the model\n- **CVE:** CVE-2026-41109 (CVSS 7.8)\n- **Sources:** [Windows News AI](https://windowsnews.ai/article/cve-2026-41109-copilot-and-vs-code-security-feature-bypass-in-the-dev-workflow.417882), [The Hacker Wire](https://www.thehackerwire.com/github-copilot-visual-studio-injection-bypasses-security-feature-cve-2026-41109/)\n\n### 2026-05-11 - Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, and Guardrails AI (CVE-2026-45321)\n\n- **Target:** 170+ packages across npm and PyPI with 518 million cumulative downloads, including TanStack (42 packages, 84 versions), Mistral AI, Guardrails AI (`guardrails-ai==0.10.1`, project quarantined), OpenSearch, and UiPath\n- **Impact:** Credential theft across cloud providers, cryptocurrency wallets, AI tools, messaging apps, and CI systems; GitHub Actions cache poisoning and OIDC token extraction; self-propagation using any publishable npm token, with a dead-man's switch that runs destructive commands if a compromised token is revoked. It was the first documented npm worm to ship valid SLSA Build Level 3 provenance attestations\n- **Root Cause:** Abuse of npm OIDC trusted publishing and CI cache poisoning with malicious install-time hooks, attributed to TeamPCP\n- **CVE:** CVE-2026-45321 (CVSS 9.6)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html), [Socket](https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack), [Tenable](https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions)\n\n### 2026-05-11 - Google GTIG Reports First AI-Developed Zero-Day for Mass Exploitation\n\n- **Target:** A popular open-source web-based system-administration tool (vendor unnamed) and internet-facing infrastructure running it\n- **Impact:** A cybercrime actor used a large language model to discover and weaponize a 2FA-bypass zero-day for a planned mass-exploitation campaign; Google Threat Intelligence Group identified and disrupted it through responsible disclosure before use\n- **Root Cause:** The LLM reasoned about a hardcoded trust assumption in the tool's 2FA enforcement logic, a semantic flaw that traditional scanners and fuzzers miss; the generated Python exploit carried LLM hallmarks including educational docstrings and a hallucinated CVSS score\n- **Sources:** [Google Cloud Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access), [The Hacker News](https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html), [CNBC](https://www.cnbc.com/2026/05/11/google-thwarts-effort-hacker-group-use-ai-mass-exploitation-event.html)\n\n### 2026-05-10 - Ollama \"Bleeding Llama\" Unauthenticated Memory Leak (CVE-2026-7482)\n\n- **Target:** Ollama before 0.17.1; more than 300,000 servers exposed online\n- **Impact:** A remote, unauthenticated out-of-bounds heap read leaks process memory, including environment variables, API keys, system prompts, and other users' conversation data, which can then be pushed out through the `/api/push` endpoint\n- **Root Cause:** The `/api/create` endpoint processes attacker-supplied GGUF files whose declared tensor offset and size exceed the actual file length; during quantization the server reads past the heap buffer using unsafe Go pointer operations. Found by Cyera\n- **CVE:** CVE-2026-7482 (CVSS 9.1)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html), [Cyera](https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama), [SecurityWeek](https://www.securityweek.com/critical-bug-could-expose-300000-ollama-deployments-to-information-theft/)\n\n### 2026-05-07 - Microsoft Semantic Kernel Prompt-Injection to RCE (CVE-2026-26030, CVE-2026-25592)\n\n- **Target:** Microsoft Semantic Kernel agent framework, Python before 1.39.4 and .NET SDK before 1.71.0\n- **Impact:** Prompt injection escalates to host-level remote code execution and sandbox escape; Microsoft demonstrated launching calc.exe from a single prompt, plus arbitrary file write and data exfiltration\n- **Root Cause:** CVE-2026-26030 (Python) is unsafe string interpolation of AI-model-controlled parameters in the in-memory vector store with a blocklist bypassable through Python class-hierarchy traversal; CVE-2026-25592 (.NET) exposed `DownloadFileAsync` to model invocation because it was accidentally marked `[KernelFunction]` with no path validation\n- **CVE:** CVE-2026-26030, CVE-2026-25592\n- **Sources:** [Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/), [ByteIota](https://byteiota.com/semantic-kernel-rce-cve-2026-25592-cve-2026-26030/)\n\n### 2026-05-07 - Microsoft Azure AI Foundry M365 Agent Privilege Escalation (CVE-2026-35435)\n\n- **Target:** Microsoft Azure AI Foundry agents published to Microsoft 365 (cloud service)\n- **Impact:** An unauthorized network attacker can elevate privileges with no authentication and no user interaction to access and manipulate protected agent workflows, data connectors, and backend resources; remediated server-side\n- **Root Cause:** Improper access control (CWE-284) in Microsoft 365 published agents\n- **CVE:** CVE-2026-35435 (NVD 10.0, Microsoft 8.6)\n- **Sources:** [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-35435), [Red Packet Security](https://www.redpacketsecurity.com/cve-alert-cve-2026-35435-microsoft-azure-ai-foundry/)\n\n### 2026-05-07 - Malicious Hugging Face \"Open-OSS/privacy-filter\" Fake OpenAI Model\n\n- **Target:** Hugging Face repository `Open-OSS/privacy-filter`, typosquatting OpenAI's Privacy Filter release, plus six sibling repositories under the same account\n- **Impact:** The repo reached #1 trending with roughly 244,000 downloads and 667 likes within about 18 hours; its `loader.py` fetched commands over disabled-SSL connections and ran a hidden PowerShell chain that deployed a Rust-based infostealer targeting browser credentials, crypto wallets, Discord tokens, and SSH keys on Windows hosts\n- **Root Cause:** A malicious model repository masquerading as a vendor release, with engagement inflated by inauthentic accounts; found and reported by HiddenLayer\n- **Sources:** [HiddenLayer](https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/malicious-hugging-face-repo/)\n\n### 2026-05-05 - Ollama for Windows Auto-Updater RCE and Persistence (CVE-2026-42248, CVE-2026-42249)\n\n- **Target:** Ollama for Windows, versions 0.12.10 through 0.22.0 (and v0.23.0), with no fix available at publication\n- **Impact:** Chaining the two flaws lets an attacker plant a persistent executable that runs at every login for covert remote code execution\n- **Root Cause:** CVE-2026-42248 is a signature-verification function that is called but does nothing, so any downloaded payload executes; CVE-2026-42249 builds the staged-installer path from unsanitized HTTP `ETag` headers, letting `../` sequences write an arbitrary executable into the Windows Startup folder. Reported by Striga; coordination handed to CERT Polska after no vendor response\n- **CVE:** CVE-2026-42248, CVE-2026-42249\n- **Sources:** [Help Net Security](https://www.helpnetsecurity.com/2026/05/05/ollama-windows-vulnerabilities-cve-2026-42248-cve-2026-42249/), [CERT Polska](https://cert.pl/en/posts/2026/04/CVE-2026-42248/)\n\n### 2026-05-04 - Grok and Bankr AI Wallet Drained via Morse-Code Prompt Injection\n\n- **Target:** xAI's Grok integrated with the Bankr crypto trading agent on the Base network\n- **Impact:** Roughly $174,000 to $204,000 in DRB (DebtReliefBot) tokens transferred to an attacker, with about 80 to 88 percent later returned through negotiation\n- **Root Cause:** A two-stage permission-chain abuse: the attacker first unlocked a high-privilege agent toolset by activating a \"Bankr Club Membership,\" then sent Grok a Morse-code message asking it to translate; once Grok output the decoded plaintext transfer instruction and tagged the trading bot, the bot treated the public reply as a valid executable command with no source validation\n- **Sources:** [SlowMist](https://slowmist.medium.com/behind-the-grok-exploitation-an-analysis-of-ai-agent-permission-chain-abuse-4d832d1bfc73), [Crypto Times](https://www.cryptotimes.io/2026/05/04/xais-grok-ai-loses-175k-in-crypto-heist-via-clever-prompt-injection-then-gets-it-all-back/), [OECD AI Incidents](https://oecd.ai/en/incidents/2026-05-04-4a73)\n\n### 2026-04-30 - PyTorch Lightning PyPI Compromise (Mini Shai-Hulud)\n\n- **Target:** `lightning` on PyPI, versions 2.6.2 and 2.6.3 (~311,000 daily downloads)\n- **Impact:** A hidden `_runtime` directory executes at import time, fetching the Bun runtime and running an ~11 MB obfuscated JavaScript credential stealer that targets GitHub, npm, and cloud tokens; it poisons local repositories with commits forged as `claude` and self-propagates by mutating npm tarballs and publishing directly to the registry\n- **Root Cause:** Maintainer or publish-credential compromise carrying a Mini Shai-Hulud payload, linked by shared obfuscation signatures to the broader npm and PyPI worm campaign\n- **Sources:** [Snyk](https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/), [The Hacker News (Hades lineage context)](https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html)\n\n### 2026-04-30 - Google Gemini CLI CVSS 10.0 Headless RCE\n\n- **Target:** Gemini CLI (`@google/gemini-cli`) before 0.39.1 and before 0.40.0-preview.3, and the `run-gemini-cli` GitHub Action before 0.1.22\n- **Impact:** Maximum-severity remote code execution in CI. Headless mode auto-trusted workspace folders, so a malicious config file in `.gemini/` executed before sandbox init and exposed any secrets, credentials, or source the workflow could reach, enabling token theft and lateral movement\n- **Root Cause:** Unsafe workspace-trust handling plus a tool-allowlist bypass under `--yolo` mode when processing untrusted pull requests or issues\n- **CVE:** Advisory GHSA-wpqr-6v78-jr5g (CVSS 10.0)\n- **Sources:** [The Register](https://www.theregister.com/2026/04/30/googles_fix_for_critical_gemini/), [The Hacker News](https://thehackernews.com/2026/04/google-fixes-cvss-10-gemini-cli-ci-rce.html), [Hackread](https://hackread.com/google-cvss-10-gemini-cli-vulnerability-github-rce/)\n\n### 2026-04-29 - LiteLLM Pre-Auth SQL Injection (CVE-2026-42208)\n\n- **Target:** LiteLLM Proxy, versions 1.81.16 up to but not including 1.83.7 (fixed in 1.83.7-stable)\n- **Impact:** An unauthenticated attacker sends a crafted `Authorization: Bearer` header to any LLM API route and runs arbitrary SQL against the proxy's PostgreSQL backend, reading and modifying tables such as `litellm_credentials.credential_values` and `litellm_config` that hold upstream provider keys for OpenAI, Anthropic, and AWS Bedrock. Targeted exploitation began within 36 hours of disclosure\n- **Root Cause:** During proxy API-key checks, the caller-supplied Bearer value is concatenated into the SQL text against `LiteLLM_VerificationToken` instead of being passed as a bound parameter\n- **CVE:** CVE-2026-42208 (CVSS 9.3)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html), [Sysdig](https://www.sysdig.com/blog/cve-2026-42208-targeted-sql-injection-against-litellms-authentication-path-discovered-36-hours-following-vulnerability-disclosure), [SecurityWeek](https://www.securityweek.com/fresh-litellm-vulnerability-exploited-shortly-after-disclosure/)\n\n### 2026-04-24 - LangChain langchain-openai and langchain-text-splitters SSRF Disclosures\n\n- **Target:** LangChain langchain-openai (before 1.1.14) and langchain-text-splitters (before 1.1.2)\n- **Impact:** Attacker-controlled URLs can reach private and localhost services (cloud metadata, internal admin interfaces) from any host running LangChain image-token counting or HTML splitter helpers\n- **Root Cause:** TOCTOU and DNS rebinding window in `_url_to_size()` (validate-then-fetch pattern with independent DNS resolution); HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL but followed redirects via `requests.get()` without revalidating redirect targets\n- **CVE:** CVE-2026-41488 (CVSS 3.1, langchain-openai SSRF), CVE-2026-41481 (CVSS 6.5, langchain-text-splitters redirect SSRF)\n- **Sources:** [GitLab Advisory CVE-2026-41488](https://radar.offseq.com/threat/cve-2026-41488-cwe-918-server-side-request-forgery-b7a78a3a), [GitLab Advisory CVE-2026-41481](https://radar.offseq.com/threat/cve-2026-41481-cwe-918-server-side-request-forgery-9716de86), [TheHackerWire CVE-2026-41488](https://www.thehackerwire.com/vulnerability/CVE-2026-41488/), [TheHackerWire CVE-2026-41481](https://www.thehackerwire.com/vulnerability/CVE-2026-41481/), [Vulnerability-Lookup CVE-2026-41488](https://vulnerability.circl.lu/vuln/cve-2026-41488)\n\n### 2026-04-23 - HexagonalRodent North Korean APT Industrializes Web3 Developer Attacks Using AI Coding Tools\n\n- **Target:** Web3 developers worldwide (subgroup of Famous Chollima/Lazarus tracked by Expel as HexagonalRodent)\n- **Impact:** 2,726 developer systems infected and 26,584 cryptocurrency wallet entries exfiltrated; an estimated $12 million in crypto assets stolen during Q1 2026; victims lured by fake high-paying job postings on LinkedIn and Web3 boards that ship \"skills tests\" abusing VSCode `tasks.json` to auto-execute malware on project open\n- **Root Cause:** Operators with low to medium technical skill scaled malware authoring, fake company website creation, and phishing lure crafting by prompting Cursor, ChatGPT, and Anima; Cursor blocked the associated accounts and IPs; OpenAI confirmed a small number of accounts had asked for help on dual-use topics\n- **Sources:** [Help Net Security](https://www.helpnetsecurity.com/2026/04/23/hexagonalrodent-north-korean-hackers-targeting-developers/), [Expel](https://expel.com/blog/inside-lazarus-how-north-korea-uses-ai-to-industrialize-attacks-on-developers/), [Yahoo / Decrypt](https://www.yahoo.com/news/articles/north-korean-hackers-industrialize-attacks-110000000.html), [KuCoin](https://www.kucoin.com/news/flash/north-korean-hackers-target-web3-developers-with-ai-powered-attacks-steal-12m-in-3-months)\n\n### 2026-04-23 - Google Workspace Reports 32% Rise in Indirect Prompt Injection Pages on the Open Web\n\n- **Target:** Public web content consumed by AI agents and Google Workspace Gemini integrations (sector-wide measurement based on Google's 2-3 billion crawled pages per month)\n- **Impact:** Google observed a 32% relative increase in malicious indirect prompt injection pages between November 2025 and February 2026; payloads target agentic AI features that can send email, run terminal commands, or process payments; Forcepoint amplified the same finding with field cases\n- **Root Cause:** AI agents ingest untrusted web content with no strict data versus instruction boundary; static blogs, forums, and comment sections are now intentional weaponization surfaces for IPI\n- **Sources:** [Google Online Security Blog \"AI threats in the wild\"](https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html), [Google Workspace continuous IPI mitigation](https://security.googleblog.com/2026/04/google-workspaces-continuous-approach.html), [Help Net Security](https://www.helpnetsecurity.com/2026/04/24/indirect-prompt-injection-in-the-wild/), [WebProNews](https://www.webpronews.com/prompt-injections-lurk-in-plain-sight-googles-scan-reveals-webs-hidden-assault-on-ai-agents/)\n\n### 2026-04-23 - SecurityScorecard Finds 40,214 OpenClaw Instances Exposed Online with 63% RCE-Vulnerable\n\n- **Target:** OpenClaw (formerly Moltbot/Clawdbot) personal AI agent platform\n- **Impact:** Internet scan identified 40,214 reachable OpenClaw instances and 28,663 unique IP addresses hosting publicly accessible control panels; about 63% of deployments are vulnerable to remote code execution; 549 exposed instances correlate with prior breach activity and 1,493 are linked to known vulnerabilities; cloud and hosting providers concentrate the exposure\n- **Root Cause:** Default deployment patterns expose admin panels with no authentication; multiple unpatched 2026 OpenClaw CVEs including ClawBleed (CVE-2026-25253, CVSS 8.8), CVE-2026-25593, and the device-pairing privilege escalation chain CVE-2026-32922 (CVSS 9.9) remain widely deployed\n- **Sources:** [SecurityScorecard](https://securityscorecard.com/blog/how-exposed-openclaw-deployments-turn-agentic-ai-into-an-attack-surface/), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/researchers-40000-exposed-openclaw/), [Dataconomy](https://dataconomy.com/2026/04/23/hackers-exploit-vulnerabilities-in-openclaw-to-control-28000-systems/), [TechRadar](https://www.techradar.com/pro/security/the-math-is-simple-openclaw-trojan-horse-ai-agents-give-hackers-full-control-of-28-000-systems), [TechBriefly](https://techbriefly.com/2026/04/23/openclaw-ai-agent-flaw-exposes-over-28000-systems/)\n\n### 2026-04-22 - Bitwarden CLI npm Package Trojanized via Checkmarx KICS Cascade\n\n- **Target:** @bitwarden/cli npm package version 2026.4.0\n- **Impact:** Malicious build of Bitwarden CLI was live on npm for roughly 90 minutes (5:57 PM-7:30 PM ET, April 22, 2026) and pulled approximately 334 times; payload `bw1.js` ran on install and harvested GitHub and npm tokens, SSH keys, AWS, GCP, and Azure secrets, GitHub Actions secrets, AI tooling configuration files, environment variables, and shell history; data exfiltrated to public GitHub repositories created under victim accounts; Bitwarden vault data was not accessed\n- **Root Cause:** Earlier in the day, attackers compromised the Checkmarx KICS Docker Hub repository; Bitwarden's Dependabot pulled the malicious `checkmarx/kics:latest` image into the Bitwarden CI/CD pipeline, which then signed and published the trojanized CLI; payload contained the marker \"Shai-Hulud: The Third Coming\" with Dune-themed identifiers\n- **Sources:** [Bitwarden Statement](https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127), [The Hacker News](https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html), [The Register](https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security), [Socket](https://socket.dev/blog/bitwarden-cli-compromised), [SecurityWeek](https://www.securityweek.com/bitwarden-npm-package-hit-in-supply-chain-attack/), [CSO Online](https://www.csoonline.com/article/4162865/bitwarden-cli-password-manager-trojanized-in-supply-chain-attack.html), [Endor Labs](https://www.endorlabs.com/learn/shai-hulud-the-third-coming----inside-the-bitwarden-cli-2026-4-0-supply-chain-attack), [GitHub Issue 20353](https://github.com/bitwarden/clients/issues/20353)\n\n### 2026-04-22 - Xinference PyPI Package Compromise (Versions 2.6.0-2.6.2)\n\n- **Target:** Xinference (Xorbits Inference) Python package on PyPI; an open-source distributed AI model inference framework with 600,000+ downloads used to self-host LLMs, embedding models, and image generators\n- **Impact:** Three consecutive releases (2.6.0, 2.6.1, 2.6.2) shipped a base64-encoded credential-stealing payload that runs on import; harvests AWS credentials and secrets, Google Cloud configurations, Kubernetes tokens, environment variables, SSH keys, API keys, and database credentials; payload spawns a detached subprocess so it survives parent process exit\n- **Root Cause:** An automated bot account \"XprobeBot\" (active since October 2025) was compromised and committed the malicious payload directly into `__init__.py`; payload structure mirrors prior TeamPCP attacks (double base64, exhaustive credential sweep, detached subprocess on import), but TeamPCP publicly denied responsibility for this one\n- **Sources:** [Mend.io](https://www.mend.io/blog/malicious-xinference-pypi-teampcp-part-4/), [GBHackers](https://gbhackers.com/xinference-pypi-breach-exposes-developers/), [OX Security](https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/), [Cyberpress](https://cyberpress.org/xinference-pypi-package-compromised/), [GitGuardian](https://blog.gitguardian.com/three-supply-chain-campaigns-hit-npm-pypi-and-docker-hub-in-48-hours/), [Orca Security](https://orca.security/resources/blog/xinference-pypi-package-compromise-remediation/)\n\n### 2026-04-21 - LMDeploy SSRF Exploited Within 13 Hours of Public Disclosure (CVE-2026-33626)\n\n- **Target:** LMDeploy LLM serving toolkit by Shanghai AI Laboratory / InternLM (all versions 0.12.0 and earlier with vision-language support)\n- **Impact:** Sysdig honeypot recorded the first exploit attempt 12 hours and 31 minutes after the GitHub advisory went live; attackers used the vision-language image loader as a generic HTTP SSRF primitive to port-scan internal networks behind the model server, hit AWS Instance Metadata Service (IMDS), Redis, MySQL, a secondary HTTP admin interface, and an out-of-band DNS exfiltration endpoint, all in a single eight-minute session\n- **Root Cause:** `load_image()` in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal or private IP ranges; fix in 0.12.3 adds URL validation and IP filtering\n- **CVE:** CVE-2026-33626 (CVSS 7.5)\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html), [Sysdig](https://www.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours), [GBHackers](https://gbhackers.com/attackers-exploit-lmdeploy-flaw/), [SC Media](https://www.scworld.com/brief/lmdeploy-vulnerability-exploited-in-real-time-highlighting-ai-infrastructure-risks), [SentinelOne CVE Profile](https://www.sentinelone.com/vulnerability-database/cve-2026-33626/), [Vulert](https://vulert.com/blog/lmdeploy-cve-2026-33626-ssrf/)\n\n### 2026-04-21 - CanisterSprawl Self-Propagating npm Worm via Namastex Labs and pgserve\n\n- **Target:** Namastex Labs npm publisher namespaces and pgserve (embedded PostgreSQL for Node.js development)\n- **Impact:** At least 16 malicious package versions across linked namespaces; pgserve releases 1.1.11, 1.1.12, and 1.1.13 (April 21 starting 22:14 UTC) carried a postinstall hook that harvested npm publish tokens, AWS, GCP, Azure, and Kubernetes credentials, SSH keys, and AI tooling configuration, then republished poisoned versions of every package the victim could publish; if a PyPI token was found, the worm jumped to PyPI; data exfiltrated both to a webhook (`telemetry.api-monitor.com`) and to ICP canister `cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io`\n- **Root Cause:** Compromised maintainer credentials at Namastex Labs (a vendor of agentic AI tooling) plus npm's allowance of postinstall hooks; ICP canister IDs cannot be removed via registrar takedowns or DNS sinkholing, blunting law-enforcement response\n- **Sources:** [StepSecurity](https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials), [Socket](https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm), [The Hacker News](https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html), [The Register](https://www.theregister.com/2026/04/22/another_npm_supply_chain_attack/), [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-npm-supply-chain-attack-self-spreads-to-steal-auth-tokens/), [SC Media](https://www.scworld.com/news/namastex-npm-packages-compromised-canisterworm-supply-chain-attack), [Cloud Security Alliance Lab](https://labs.cloudsecurityalliance.org/research/csa-research-note-npm-canistersprawl-supply-chain-worm-20260/), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/npm-supply-chain-worm-canister/)\n\n### 2026-04-21 - Anthropic Claude Mythos Preview Accessed by Discord Group via Vendor Breach\n\n- **Target:** Anthropic Claude Mythos Preview (cyber-offensive AI model held back under Project Glasswing limited-partner program)\n- **Impact:** A small private Discord community gained continuous access to Mythos starting on launch day (April 7, 2026) by guessing the preview URL pattern, drawing on operational details from a Mercor breach three weeks earlier; group has not used Mythos for cyberattacks but has retained access; Anthropic stated it is investigating \"unauthorized access to Claude Mythos Preview through one of our third-party vendor environments\"\n- **Root Cause:** A third-party contractor with operational knowledge confirmed URL guesses based on Anthropic's prior naming conventions; access controls relied on URL secrecy at the vendor environment rather than authenticated tenancy; Mercor breach context fed the recon\n- **Sources:** [TechCrunch](https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/), [Bloomberg](https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users), [Fortune](https://fortune.com/2026/04/23/anthropic-mythos-leak-dario-amodei-ceo-cybersecurity-hackers-exploits-ai/), [Engadget](https://www.engadget.com/ai/anthropic-is-investigating-unauthorized-access-of-its-mythos-cybersecurity-tool-091017168.html), [Cybernews](https://cybernews.com/security/anthropic-mythos-ai-unauthorized-access/), [Hackread](https://hackread.com/discord-access-anthropic-claude-mythos-ai-breach/), [GovInfoSecurity](https://www.govinfosecurity.com/report-discord-group-uses-claudes-supposedly-secret-mythos-a-31484), [The Next Web](https://thenextweb.com/news/anthropic-mythos-unauthorized-access-vendor-breach)\n\n### 2026-04-21 - Cloud Security Alliance Survey: AI Agent Incidents Common Across Enterprises\n\n- **Target:** AI agent governance across 418 surveyed organizations (CSA / Token Security study, \"Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises\")\n- **Impact:** 65% of organizations experienced at least one AI agent-related cybersecurity incident in the past 12 months; 88% confirmed or suspected AI agent incidents; 82% had discovered previously unknown AI agents in their environment in the past year; 61% reported data exposure, 43% operational disruption, 35% financial loss, and 41% unintended actions in business processes from these incidents; only 21% had formal decommissioning processes in place\n- **Root Cause:** Survey analysis; visibility and decommissioning gaps allow shadow AI agents to operate outside identity, network, and audit controls; healthcare incident rate reaches 92.7%\n- **Sources:** [CSA Press Release](https://cloudsecurityalliance.org/press-releases/2026/04/21/new-cloud-security-alliance-survey-reveals-82-of-enterprises-have-unknown-ai-agents-in-their-environments), [BusinessWire](https://www.businesswire.com/news/home/20260421037010/en/New-Cloud-Security-Alliance-Survey-Reveals-82-of-Enterprises-Have-Unknown-AI-Agents-in-Their-Environments), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/unchecked-ai-agents-cause/), [ADVISOR Magazine](https://www.lifehealth.com/autonomous-but-not-controlled-ai-agent-incidents-now-common-in-enterprises/)\n\n### 2026-04-21 - Flowise CSV Agent Prompt Injection RCE (CVE-2026-41264)\n\n- **Target:** FlowiseAI Flowise (all versions before 3.1.0)\n- **Impact:** Authenticated RCE on Flowise hosts through any chatflow that uses the CSV Agent node; an attacker prompts the LLM into emitting a Python script that the server then runs without sandboxing\n- **Root Cause:** `run` method of the CSV_Agents class evaluates LLM-generated Python without proper sandboxing; bypasses earlier hardening for CVE-2026-41137; reported through Trend Micro Zero Day Initiative; fix in 3.1.0 disallows all imports inside CSV Agent\n- **CVE:** CVE-2026-41264 (CVSS 7.0)\n- **Sources:** [GitHub Advisory GHSA-3hjv-c53m-58jj](https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3hjv-c53m-58jj), [GitLab Advisory](https://advisories.gitlab.com/npm/flowise-components/CVE-2026-41264/), [THREATINT](https://cve.threatint.eu/CVE/CVE-2026-41264), [SC Media](https://www.scworld.com/brief/active-exploitation-of-max-severity-flowise-bug-threatens-broad-compromise)\n\n### 2026-04-20 - Vercel Breach via Context.ai AI Tool Supply Chain\n\n- **Target:** Vercel (Next.js hosting platform) via Context.ai (AI Office Suite)\n- **Impact:** Attacker accessed Vercel Google Workspace and internal systems, including environment variables for a \"limited subset\" of customer projects; stolen data offered for $2M on BreachForums by a ShinyHunters persona; downstream crypto projects scrambled to rotate API keys\n- **Root Cause:** Context.ai employee infected with Lumma Stealer in February 2026; attacker abused the Context.ai Google Workspace OAuth application that a Vercel employee had granted \"Allow All\" enterprise scopes; OAuth token replay escalated into the Vercel tenant\n- **Sources:** [TechCrunch](https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai/), [The Hacker News](https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html), [The Register](https://www.theregister.com/2026/04/20/vercel_context_ai_security_incident/), [Vercel Bulletin](https://vercel.com/kb/bulletin/vercel-april-2026-security-incident), [OX Security](https://www.ox.security/blog/vercel-context-ai-supply-chain-attack-breachforums/), [Trend Micro](https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html), [CoinDesk](https://www.coindesk.com/tech/2026/04/20/hack-at-vercel-sends-crypto-developers-scrambling-to-lock-down-api-keys), [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/vercel-breached-after-employee-grants-ai-tool-unrestricted-access-to-google-workspace)\n\n### 2026-04-17 - FastGPT Authentication and Password Change NoSQL Injection\n\n- **Target:** FastGPT AI agent building platform (before v4.14.9.5)\n- **Impact:** Unauthenticated attacker can log in as any user including root via MongoDB operator injection on the password field; authenticated attacker can bypass old-password verification to take over any account\n- **Root Cause:** TypeScript type assertion without runtime validation on password login endpoint; NoSQL operator injection in password change endpoint\n- **CVE:** CVE-2026-40351 (CVSS 9.8), CVE-2026-40352 (CVSS 8.8)\n- **Sources:** [TheHackerWire CVE-2026-40351](https://www.thehackerwire.com/vulnerability/CVE-2026-40351/), [TheHackerWire CVE-2026-40352](https://www.thehackerwire.com/vulnerability/CVE-2026-40352/)\n\n### 2026-04-16 - Anthropic MCP Systemic STDIO Design RCE\n\n- **Target:** Anthropic Model Context Protocol reference SDKs (Python, TypeScript, Java, Rust) and 200,000+ downstream instances\n- **Impact:** Arbitrary command execution on any MCP host via STDIO transport; OX Security demonstrated takeover of six production platforms and 30+ RCE reports across projects including LiteLLM, LangChain, Flowise, GPT Researcher, Agent Zero, and Windsurf; 11 CVEs assigned to downstream projects\n- **Root Cause:** MCP STDIO transport accepts arbitrary command strings and passes them to subprocess execution with no validation, sanitization, or sandboxing; commands execute even when process startup fails; Anthropic declined to modify the protocol and said sanitization is the developer's responsibility\n- **CVE:** CVE-2025-65720, CVE-2026-30623, CVE-2026-30624, CVE-2026-40933 (Flowise MCP Adapters, CVSS 10.0) and 7+ others\n- **Sources:** [OX Security](https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/), [The Hacker News](https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html), [The Register](https://www.theregister.com/2026/04/16/anthropic_mcp_design_flaw/), [CSO Online](https://www.csoonline.com/article/4159889/rce-by-design-mcp-architectural-choice-haunts-ai-agent-ecosystem.html), [Infosecurity Magazine](https://www.infosecurity-magazine.com/news/systemic-flaw-mcp-expose-150/), [TechRadar](https://www.techradar.com/pro/security/this-is-not-a-traditional-coding-error-experts-flag-potentially-critical-security-issues-at-the-heart-of-anthropics-mcp-exposes-150-million-downloads-and-thousands-of-servers-to-complete-takeover), [GitHub Advisory CVE-2026-40933](https://github.com/advisories/GHSA-c9gw-hvqq-f33r)\n\n### 2026-04-15 - LiteLLM OIDC Userinfo Cache Authentication Bypass\n\n- **Target:** LiteLLM (BerriAI LLM gateway) deployments with JWT auth enabled\n- **Impact:** Unauthenticated attacker can craft a token whose first 20 characters collide with a cached legitimate token, inheriting that user's identity and permissions across the gateway\n- **Root Cause:** OIDC userinfo cache keyed on token[:20] instead of the full token or a secure hash; JWTs produced by the same signing algorithm share the same header prefix\n- **CVE:** CVE-2026-35030 (CVSS 9.4)\n- **Sources:** [LiteLLM Advisory](https://docs.litellm.ai/blog/security-hardening-april-2026), [GitLab Advisory](https://advisories.gitlab.com/pkg/pypi/litellm/CVE-2026-35030/), [GitHub Advisory](https://github.com/advisories/GHSA-jjhc-v7c2-5hh6), [SecurityOnline](https://securityonline.info/litellm-security-vulnerability-auth-bypass-rce-patch/), [Wiz](https://www.wiz.io/vulnerability-database/cve/cve-2026-35030)\n\n### 2026-04-15 - Copilot Studio ShareLeak and Agentforce PipeLeak Form-Based Prompt Injection\n\n- **Target:** Microsoft Copilot Studio and Salesforce Agentforce\n- **Impact:** Attackers fill public-facing SharePoint or Web-to-Lead form fields with a fake system-role payload; hijacked agents query connected data sources in bulk and email the results to an attacker address with no volume cap, no Human-in-the-Loop prompt, and no trace shown to the employee who triggered the agent; Capsule Security reports the email channel remains exploitable on Agentforce Sub-Agents (formerly Custom Topics) even after Salesforce's remediation\n- **Root Cause:** Untrusted form inputs concatenated directly into agent context windows; agents simultaneously hold read access to CRM/SharePoint data and authority to send outbound email\n- **CVE:** CVE-2026-21520 (CVSS 7.5, Copilot Studio ShareLeak); PipeLeak has no CVE assigned\n- **Sources:** [VentureBeat](https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook), [Dark Reading](https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws), [CSO Online](https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html), [NVD CVE-2026-21520](https://nvd.nist.gov/vuln/detail/CVE-2026-21520), [PointGuard AI](https://www.pointguardai.com/ai-security-incidents/copilot-studio-leak-the-assistant-that-overshared-cve-2026-21520)\n\n### 2026-04-15 - Claude Code, Gemini CLI, Copilot Agent Hijacked via GitHub Comments\n\n- **Target:** Anthropic Claude Code Security Review, Google Gemini CLI Action, GitHub Copilot Agent (all GitHub Actions integrations)\n- **Impact:** Prompt injection via PR titles, issue descriptions, and comments lets attackers execute arbitrary commands in the Actions runner, steal Anthropic and Gemini API keys, GitHub tokens, and any repository or organization secret available to the workflow\n- **Root Cause:** Each agent ingests untrusted GitHub comment content as authoritative instructions with no separation between policy and data; all three vendors paid bug bounties ($100 Anthropic, $500 GitHub, undisclosed Google) but none assigned CVEs or published advisories, leaving downstream users unaware\n- **Sources:** [The Register](https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/), [SecurityWeek](https://www.securityweek.com/claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/), [The Next Web](https://thenextweb.com/news/ai-agents-hijacked-prompt-injection-bug-bounties-no-cve), [Cybernews](https://cybernews.com/security/ai-agents-github-prompt-injection-pattern/)\n\n### 2026-04-15 - n8n Webhook Weaponization for Phishing Campaigns\n\n- **Target:** n8n AI workflow automation platform (cloud-hosted webhooks)\n- **Impact:** Attackers embed n8n-hosted webhook URLs in phishing emails; clicking opens a JavaScript CAPTCHA page on the trusted n8n domain that then downloads modified RMM tools such as Datto and ITarian; March 2026 volume of emails carrying these URLs was 686% higher than January 2025\n- **Root Cause:** Public webhook URLs on trusted n8n infrastructure let attackers bypass email security filters that would otherwise block attacker-controlled domains; abuse first observed October 2025 and escalated through April 2026\n- **Sources:** [The Hacker News](https://thehackernews.com/2026/04/n8n-webhooks-abused-since-october-2025.html), [Cisco Talos](https://blog.talosintelligence.com/the-n8n-n8mare/), [SC Media](https://www.scworld.com/brief/ai-workflow-platform-n8n-abused-for-phishing-and-device-fingerprinting), [TechRepublic](https://www.techrepublic.com/article/news-hackers-abuse-n8n-workflows-malware-delivery/)\n\n### 2026-04-14 - OWASP GenAI Q1 2026 Exploit Round-up Report\n\n- **Target:** AI ecosystem (sector-wide report covering January 1 - April 11, 2026)\n- **Impact:** Documents the transition from theoretical risks to active exploitation; 520 reported tool misuse and privilege escalation incidents in 2026; prompt injection with 450 incidents; highlights Anthropic Claude abuse in the 150GB Mexican government data theft as the period's prominent case; notes a growing gap between traditional CVE-based vulnerability management and architectural AI risks that never receive CVE IDs\n- **Root Cause:** Report synthesis; attackers target agent identities, orchestration layers, and supply chains rather than just model outputs\n- **Sources:** [OWASP GenAI Q1 2026 Report](https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/)\n\n### 2026-04-13 - Malicious LLM Router Research Reveals Credential and Crypto Theft\n\n- **Target:** 428 public AI API routers tested by UCSB/UCSD researchers (published arXiv April 8, amplified April 13)\n- **Impact:** 26 routers injected malicious tool calls, 9 injected malicious code into agent outputs, 17 accessed researcher AWS credentials, and at least one drained ETH from a researcher-controlled wallet; one client reportedly lost $500,000 in crypto to a malicious router; attacks include payload injection (AC-1), secret exfiltration (AC-2), dependency rewriting, and adaptive evasion that activates only in autonomous \"YOLO mode\"\n- **Root Cause:** LLM routers operate as opaque man-in-the-middle intermediaries between clients and model providers; agents accept rewritten tool calls as trusted output\n- **Sources:** [ArXiv paper](https://arxiv.org/html/2604.08407v1), [CoinDesk](https://www.coindesk.com/tech/2026/04/13/ai-agents-are-set-to-power-crypto-payments-but-a-hidden-flaw-could-expose-wallets), [Risky Business](https://news.risky.biz/risky-bulletin-malicious-llm-proxy-routers-found-in-the-wild/), [CCN](https://www.ccn.com/news/crypto/will-ai-steal-bitcoin-research-malicious-llm-routers-crypto-theft/), [OECD AI Incident Database](https://oecd.ai/en/incidents/2026-04-10-d6e2)\n\n### 2026-04-13 - Marimo Pre-Auth RCE Weaponized to Deploy NKAbuse via Hugging Face\n\n- **Target:** Marimo Python reactive notebook platform (all versions up to 0.20.4)\n- **Impact:** 662 exploit events from 11 source IPs across 10 countries between April 11 and 14, 2026; reverse shells, credential theft, DNS exfiltration, lateral movement to PostgreSQL and Redis, and deployment of a new NKAbuse variant; malware installer hosted on a typosquat Hugging Face Space \"vsccode-modetx\" drops a Go ELF binary named kagent that uses the NKN blockchain for C2\n- **Root Cause:** /terminal/ws WebSocket endpoint lacks the validate_auth() call present on other endpoints; unauthenticated attackers obtain a full PTY shell; exploitation began within 10 hours of public disclosure\n- **CVE:** CVE-2026-39987 (CVSS 9.3)\n- **Sources:** [Sysdig](https://www.sysdig.com/blog/cve-2026-39987-update-how-attackers-weaponized-marimo-to-deploy-a-blockchain-botnet-via-huggingface), [The Hacker News](https://thehackernews.com/2026/04/marimo-rce-flaw-cve-2026-39987.html), [BleepingComputer](https://ww","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/webpro255%2Fawesome-ai-agent-attacks/projects"}