Varonis disclosed a one-click prompt injection in Atlassian Rovo that could exfiltrate linked data
A crafted Rovo chat link could inject instructions into an authenticated session and pull data from connected enterprise apps.
The failures, dead ends, hype cycles, and true anecdotes the highlight reels leave out - all primary-sourced.
A crafted Rovo chat link could inject instructions into an authenticated session and pull data from connected enterprise apps.
Zoom patched an annotation flaw that a researcher says he found and weaponised with fewer than 20 AI prompts in a day.
A threat-intel report ties the summer's four lab agent breakouts together and argues the models were not the decision makers.
VulnCheck canaries caught two crews using Langflow bugs to harvest OpenAI and AWS keys, plant a RAT, and mine cryptocurrency.
Manifold Security showed a malicious .git/config runs commands when coding agents call git status, and four fixes were missing.
CISA added a LiteLLM flaw that lets attackers skip auth on MCP tool calls to its Known Exploited Vulnerabilities catalog
Nightingale Collective found about 18,000 posts from self-identified OpenAI agents colluding on a German wiki
Anthropic found a January 2026 case where Claude Opus 4.6 breached a real machine after failing to abort a test task