AI Security & LLM Threat Collection
LLM security, prompt injection, AI agent risk, and AI governance coverage.
2026-07-21 · MEDIUMNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
2026-07-20 · MEDIUMJadePuffer agentic attacks now target AI model data with ransomware
2026-07-20 · MEDIUMWould you leave a comfortable Network Security role for AI Security?
2026-07-20 · HIGHHugging Face breached by autonomous AI agent
2026-07-20 · HIGHCapital One Open Sources AI-Powered VulnHunter Security Tool
2026-07-20 · MEDIUM⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
2026-07-20 · HIGHWorld's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
2026-07-20 · HIGHNearly half of open-source AI projects never reach production
2026-07-20 · MEDIUMCapital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
2026-07-19 · HIGHCVE-2026-15322: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the
CVE-2026-15322
2026-07-19 · HIGH
CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope
CVE-2026-15091
2026-07-19 · HIGH
CVE-2026-58195: Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone
CVE-2026-58195
2026-07-19 · MEDIUM
What AI cyber security platforms are spearheading the field.
2026-07-19 · HIGHCVE-2026-57860: ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i
CVE-2026-57860
2026-07-18 · MEDIUM
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
2026-07-17 · MEDIUMAI security project: PromptShield
2026-07-17 · MEDIUMPodcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
2026-07-17 · MEDIUME.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
2026-07-17 · MEDIUMIf you've given an AI agent real credentials, how are you scoping what it can reach?
2026-07-16 · HIGHMCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-59950CVE-2026-59950
2026-07-16 · HIGH
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52869CVE-2026-52869
2026-07-16 · HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVE-2026-52870CVE-2026-52870
2026-07-16 · MEDIUM
Claude Chrome extension flaw lets malicious extensions trigger AI actions
2026-07-16 · MEDIUMWith AI, Your Entire Internet History is Attributable to you Personally
2026-07-16 · MEDIUMTop 10 Data Center and AI Infrastructure Security Risks
2026-07-16 · MEDIUMAI Data Centers Are Being Built Faster Than They Can Be Secured
2026-07-16 · MEDIUMPlease Stop Making Me Opt Out of AI
2026-07-16 · MEDIUMAI Agent for reconaissasion
2026-07-15 · HIGH@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
CVE-2026-54504CVE-2026-54504
2026-07-15 · MEDIUM
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
2026-07-15 · HIGHLangBot: Authenticated RCE Via MCP Configuration
CVE-2026-54449CVE-2026-54449
2026-07-15 · MEDIUM
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
2026-07-15 · MEDIUMWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
2026-07-14 · HIGHNetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
CVE-2026-54446CVE-2026-54446
2026-07-14 · HIGH
yutu: Arbitrary File Write via MCP `caption-download` Tool
CVE-2026-50158CVE-2026-50158
2026-07-14 · MEDIUM
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
2026-07-14 · MEDIUMFrontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
2026-07-14 · MEDIUMSource-reviewing 200+ self-hosted multi-tenant AI/SaaS apps for tenant isolation: 78 leaked across tenants (the "un-retrofitted read sibling")
2026-07-14 · MEDIUMEnhancing the Threat Intelligence AI Model with Technical Knowledge About Windows Kernel Mode Malware
2026-07-13 · MEDIUMExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"
2026-07-13 · MEDIUMContext Bombs: Using AI Guardrails as a defensive mechanism
2026-07-13 · MEDIUM'Yellow Teams' Are Defining the Future of AI Security
2026-07-13 · MEDIUMEvery AI coding agent writes the secrets you paste straight to a plaintext history file — and nobody scans it
2026-07-13 · MEDIUMNow, defenders are embracing the prompt injection, too
2026-07-13 · MEDIUM⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
2026-07-13 · MEDIUMA hardware security AI assistant that checks chips for hidden backdoors
2026-07-13 · MEDIUMParticipants Needed: Master's Research on AI Governance & the EU AI Act
2026-07-12 · MEDIUMIT Governance vs AI Governance
2026-07-12 · MEDIUMWhat's stopping big orgs to replicate those AI Security startups themselves?
2026-07-12 · MEDIUMMicrosoft is rewriting Windows patch guidance because of AI - Help Net Security
2026-07-11 · MEDIUMLooking for Cybersecurity Contributors – Building an Open-Source AI Bot Detection Project
2026-07-11 · MEDIUMFreelancing on cybersec/ai
2026-07-11 · MEDIUM'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
2026-07-11 · MEDIUMA degree in CS or AI engineering & robotics
2026-07-10 · HIGHmcp-atlassian: Arbitrary server-side file read via attachment upload
2026-07-10 · HIGHmcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
2026-07-10 · MEDIUMTraining recommendations for SOC teams in the age of AI?
2026-07-10 · MEDIUMThe Replicant in Your Directory: AI Agents and the Identity Security Gap
2026-07-10 · MEDIUMAI Coding: Do Security Risks Outweigh Productivity Gains?
2026-07-10 · MEDIUMCrypto Investigations using AI
2026-07-10 · MEDIUMCan AI imitate APT behavior well enough to confuse attribution?
2026-07-10 · MEDIUMCan AI-generated adversaries break TTP-based attribution? (arXiv 2026)
2026-07-10 · MEDIUM'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism
2026-07-10 · MEDIUMNew research: Why no single AI agent harness wins every cybersecurity task
2026-07-10 · MEDIUM"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
2026-07-10 · MEDIUM‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
2026-07-09 · MEDIUMMicrosoft expects more Windows security updates from AI-discovered flaws
2026-07-09 · MEDIUMNew Forg365 phishing platform uses AI to target Microsoft 365 accounts
2026-07-09 · MEDIUMUK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
2026-07-09 · HIGHPhantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
2026-07-09 · MEDIUMAI Gateways Offer Attackers the Keys to the Kingdom
2026-07-09 · MEDIUMAI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
2026-07-09 · MEDIUMMOD REQUEST: Can you ban the excessive AI posters please?
2026-07-09 · MEDIUMAI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
2026-07-08 · MEDIUMLone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
2026-07-08 · MEDIUMAI agents went from "cool demo" to "exploiting CVEs in 10 hours"
2026-07-08 · MEDIUMAre companies thinking about insurance/liability for AI tool usage, or is that not on the radar yet?
2026-07-08 · MEDIUMAI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
2026-07-08 · MEDIUMHPC AI Workloads Need Runtime Security. The Architecture Already Exists.
2026-07-08 · MEDIUMResearchers Find New GhostApproval Bug in Many AI Coding Assistants
2026-07-08 · MEDIUMGoogle Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
2026-07-08 · MEDIUMCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
2026-07-07 · MEDIUMDialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
2026-07-07 · HIGHBetter Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
2026-07-07 · MEDIUMOpen-source AI security risk register mapped to MITRE ATLAS, OWASP LLM/Agentic Apps, and NIST AI 100-2
2026-07-07 · MEDIUMCheckmarx MCP
2026-07-06 · HIGHCoder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-55436CVE-2026-55436
2026-07-06 · HIGH
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
CVE-2026-55786CVE-2026-55786
2026-07-06 · MEDIUM