Home/ Blog/ Topics/ AI & LLM security
Topic

AI & LLM security

Security of AI systems: agent and large-language-model vulnerabilities, prompt injection, model supply chain, and Model Context Protocol (MCP) tooling.

Security news

One logged-in Langflow user can run any command on the server, and its code lockdown doesn't stop it

A critical Langflow flaw (CVE-2026-19295, CVSS 9.9) lets any authenticated user run OS commands on the server and bypasses the

Security news

Encrypted page instructions make Grok leak your chat history

Adversa AI showed encrypted web-page instructions can make xAI's Grok leak your chat history and session data. Why plaintext filters miss it, and how to defend.

Security news

Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other

Anthropic's red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.

Security news

Shared AI logs leak API keys and PII: OpenAI, Anthropic, and Google reasoning traces can be decoded

Researchers decoded 315,320 public AI reasoning blocks from OpenAI, Anthropic, and Google, recovering 182 credentials and 367 PII artifacts. What to do now.

Security news

A poisoned Trivy scanner, not LiteLLM, exposed 2,500 organizations' CI/CD secrets

CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign.

Security news

OpenAI paused Astra over autonomous exploit-writing

OpenAI paused Astra after tests could not rule out autonomous exploit capability. For defenders the near-term risk is automated n-day exploitation.

Security news

Atlassian Rovo could leak Jira and Confluence data; one of two attack routes is unconfirmed as fixed

Two firms found Atlassian Rovo could be tricked into leaking Jira, Confluence and SharePoint data. One attack route is patched; the other is unconfirmed.

Security news

Langflow's auto-login default gives any stranger admin, then RCE

CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.

Security news

An AI agent hit 460 servers on its own, but known CVEs did the breaking

A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.

Security news

Anthropic's own AI models breached three real companies in tests

Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.

Security news

Ruflo's unauthenticated AI agent bridge runs code (CVE-2026-59726); patching won't evict the poisoned memory

Ruflo exposed an unauthenticated MCP bridge to 233 tools, so one request gets full remote code execution (CVE-2026-59726).

Deep dive

For this week's most-exploited bugs, the patch was the easy part

This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.

Security news

A single ChatGPT link could plant a rogue AI agent in your org

Zenity Labs' AgentForger let one crafted ChatGPT link forge a self-running AI agent wired to your connected apps. OpenAI fixed it. Here's what to watch.

Security news

Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand's finance ministry

An attacker ran an unattended AI agent to hack Thailand's finance ministry. It used no new exploit, and defenders catch it by watching host actions.

Security news

Langflow's code-validation endpoint just produced its second unauthenticated RCE

CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow's validate endpoint, actively exploited and added to CISA's KEV catalog.

Deep dive

The week's scariest ‘AI’ bugs weren't about AI. They were the confused deputy.

This week's headline ‘AI’ vulnerabilities in Grafana and Apache Camel are the 1988 confused-deputy flaw, the same one that hit Fastify, Directus and OpenShift

Security news

An AI agent breached Hugging Face. Blocklists can't catch it.

Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.

Security news

In Apache Camel, a manipulated AI reply can quietly redirect what the server does next

CVE-2026-49042 lets a prompt-injected AI model set hidden Apache Camel headers via tool-call arguments, reaching code execution or SSRF on exposed routes.

Security news

NadMesh turns exposed AI servers into cloud-key harvesters

NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.

Security news

A rogue extension can still make Claude in Chrome read your Gmail

A rogue browser extension can forge a click that makes Claude for Chrome read your Gmail, Docs, and Calendar, unpatched across eight releases.

Security news

How a PNG in a pull request makes AI agents leak secrets

Researchers hid prompt-injection text inside a PNG in a pull request and made AI coding agents read .env and leak the secrets.

Security news

A rigged Jira ticket can trick the mcp-atlassian AI connector into leaking server files

mcp-atlassian before 0.22.0 reads files off its own host when a caller or a prompt-injected agent supplies a server-side path.

Security news

Three attacks in one week turned AI coding agents into an unmonitored way onto your network

HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.

Security news

A Google chatbot 'edit' permission was really a code-execution grant

Google's Dialogflow CX let one edit permission run code across every chatbot in a project.

Security news

A public GitHub issue made an AI agent leak a private repo. No patch closes this class.

A crafted public GitHub issue tricked an AI Agentic Workflow into posting a private repo's contents as a public comment. Why no patch closes this class.

Security news

The first AI-run ransomware locked a database with a key it never saved

The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.

Security news

Cursor's AI agent trusted the content it read, and that content could switch off its sandbox

Two critical Cursor flaws, DuneSlide (CVE-2026-50548/50549, CVSS 9.8), let a poisoned MCP server or web result overwrite the sandbox binary and run code.

Security news

A rigged puzzle talked six AI browsers into leaking a developer's SSH keys. One patch won't save you.

A game-themed web page talked six AI browsers into leaking a developer's SSH keys. Why patching one vendor is not the fix, and what to watch instead.

Security news

AI keeps inventing web addresses that do not exist. Attackers now buy them first.

Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.

Deep dive

The code was clean. The toolchain that shipped it was the attack.

This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.

Security news

The repo is clean. Your AI coding agent is what hands the attacker a shell.

Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.

Security news

Open the wrong repo and Amazon Q ran its config file as you, AWS keys included

Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.

Deep dive

The dangerous vulnerabilities this week were already old.

The vulnerability classes that actually shipped this week are the same five from 2010, even in new AI tooling. The pattern, and what to do.

Security news

A rigged container image can seize root on the host running Docker's AI agent tools

CVE-2026-55887 lets a malicious container image escape Docker's MCP Gateway and run code as root on the host. Rated 8.7.

Security news

Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams

Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.

Security news

A new Mac backdoor is built to fool the AI that inspects it

macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.

Security news

Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.

The US used export-control powers to pull a frontier AI model that finds software bugs at scale.

Security news

Your AI agent trusts your own computer. One web page turns that into a takeover.

Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.

Security news

vLLM's earlier patch only hid this AI-server bug. Re-enable embeddings and you are still exposed

CVE-2026-56340 lets a crafted tensor crash vLLM (CVSS 8.8) with a path to memory corruption. It only bites if you re-enabled prompt embeds. Fix is 0.13.0.

Security news

One tracing header can make a LangSmith server hand over its files

LangSmith SDK before 0.8.18 lets a crafted tracing header read arbitrary files off any server running TracingMiddleware. Upgrade now; it is the second such bug.

Security news

The app you're testing can hijack the AI agent testing it: Appium MCP's XSS flaw

An XSS flaw in Appium's official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.

Security news

A single rigged document can turn Langflow's file reader into full server takeover

A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.

Security news

One Langflow account can now run every other user's AI workflow

A critical IDOR in Langflow (CVE-2026-55255, CVSS 9.9) lets any logged-in user run another user's AI flow. Upgrade to 1.9.1. The real problem is the pattern.

Security news

Mastra's npm packages passed inspection, then turned hostile a day later

Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload.

Security news

SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs

SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.