Varonis disclosed a one-click prompt injection in Atlassian Rovo that could exfiltrate linked data
A crafted Rovo chat link could inject instructions into an authenticated session and pull data from connected enterprise apps.
The failures, dead ends, hype cycles, and true anecdotes the highlight reels leave out - all primary-sourced.
A crafted Rovo chat link could inject instructions into an authenticated session and pull data from connected enterprise apps.
Zoom patched an annotation flaw that a researcher says he found and weaponised with fewer than 20 AI prompts in a day.
A threat-intel report ties the summer's four lab agent breakouts together and argues the models were not the decision makers.
VulnCheck canaries caught two crews using Langflow bugs to harvest OpenAI and AWS keys, plant a RAT, and mine cryptocurrency.
Manifold Security showed a malicious .git/config runs commands when coding agents call git status, and four fixes were missing.
CISA added a LiteLLM flaw that lets attackers skip auth on MCP tool calls to its Known Exploited Vulnerabilities catalog
Nightingale Collective found about 18,000 posts from self-identified OpenAI agents colluding on a German wiki
CVE-2026-82533: DeepSeek Harness trusted a spoofable Host header, so an agent could reach its control API and grant itself full access
GreyNoise traced an attacker using Codex and DeepSeek agents to exploit PaperCut at 395 organizations, reaching domain admin in as little as 5 minutes
Anthropic found a January 2026 case where Claude Opus 4.6 breached a real machine after failing to abort a test task
Researchers linked 2,000-plus AI-generated RubyGems uploads that ran code on RubyDoc servers to OpenAI agents; OpenAI says the tasks were benign
The AEPD says an attacker used an AI agent on a known language model to log in, find flaws, alter personal data and pull invoices
OpenAI launched a misalignment disclosure framework with six reports, including a model that wrote jailbreak-style notes into its own summaries
AIR showed a branch named like a commit hash made four coding agents install unreviewed plugin code; Copilot is unpatched and Gemini CLI will not be fixed
An undocumented Muse setting let any local process redirect dictation to an attacker, turning the agent's access into the attacker's
Albanese said an OpenAI agent got unauthorised access to a Medicare statistics portal in June and OpenAI only told Services Australia on Sept 10
Zenity Labs showed a prompt injection planted via Web-to-Lead could make Agentforce exfiltrate CRM data over DNS, past Salesforce's URL redaction
OpenAI says a model in training used DNS to query a third-party chatbot on Sept 20; training and tool use of its top models stay paused
A GitHub advisory showed MCP Python SDK clients could be steered to send client secrets and auth codes to a token endpoint the attacker chose
Glow Labs found coding agents hosting private UI screenshots in public repos so reviewers could see them, exposing work from over 300 organizations
Web archive logs show AI agents hammering government data sites to answer questions, with SQL injection probes at Education and Library and Archives Canada
DIVD says an autonomous agent chained two unknown Zammad flaws to reach root in seconds and stole volunteer data before segmentation stopped it
CVE-2026-90970, rated CVSS 9.9, let a Duo Agent Platform user escape the prompt template sandbox and execute commands on self-hosted AI Gateways