Machine Speed
AI-Cyber Intel
The Board
Watchlist
Briefs
Newsletter
About
RSS
☀
Light
Lanes
Capability
86
Policy
56
Defense
82
Attacks
92
Markets
29
Attacks on AI systems
Attacks aimed at AI itself: prompt injection, poisoned agent tools and packages, exposed AI infrastructure, and stolen or copied model access.
Back to the Watchlist
78
Items
Jul 2
First
Sep 28
Latest
Threads in this topic
AI infrastructure as attack surface
23
Sep 28
Sep 28
Defense
NVIDIA puts agent policy enforcement on a separate chip from the agent
NVIDIA (via Help Net Security) ↗
Sep 17
Defense
A scan of public MCP configuration files finds one credential in eight hardcoded
Hush Security (via PR Newswire) ↗
Sep 16
Capability
A coding agent fine-tuned and redeployed the model it was running on, without being told to
Irregular ↗
Sep 11
Attacks
A maximum-severity GitLab flaw drew in-the-wild probes the day it was patched, beside a critical flaw in its AI assistant
GitLab and watchTowr (via The Hacker News) ↗
Sep 11
Defense
A census of self-hosted AI infrastructure counts 36,769 reachable endpoints and almost none behind a login
Mysterium VPN (via Security Affairs) ↗
Sep 11
Defense
Another unauthenticated code-execution flaw is published against the SGLang inference server
OpenCVE / CERT/CC ↗
Sep 8
Defense
A flaw in DeepSeek's agent harness let a sandboxed agent turn its own confinement off with one command
OX Security / OpenCVE ↗
Sep 2
Defense
Two chained flaws let unauthenticated callers reach data through Grafana's MCP server
Pillar Security ↗
Sep 2
Attacks
CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog
CISA (record read via CIRCL Vulnerability-Lookup) ↗
Sep 1
Attacks
Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials
VulnCheck (via The Hacker News) ↗
Aug 28
Attacks
VulnCheck logs more than 15,000 successful exploitation attempts against Langflow
VulnCheck ↗
Aug 28
Attacks
Metasploit ships public exploit modules for two AI application platforms
Rapid7 ↗
Aug 27
Defense
ServiceNow patches three flaws rated CVSS 10.0 in its AI Platform
ServiceNow (via The Hacker News) ↗
Aug 27
Attacks
Wiz honeypots record attackers exploiting MCP servers and self-hosted AI stacks
Wiz ↗
Aug 26
Attacks
Microsoft reports attackers compromising self-hosted AI gateways and orchestration platforms for credentials and cryptomining
Microsoft Threat Intelligence ↗
Aug 25
Defense
RAND publishes a 262-control framework for securing AI model weights at security level 3
RAND ↗
Aug 25
Defense
Oasis Security discloses a NemoClaw flaw that lets a malicious webpage poison a developer's local AI model
Oasis Security (via The Hacker News) ↗
Aug 18
Attacks
Attackers exploit a critical SSRF flaw in the MLflow AI platform to steal cloud credentials
Decipher (reporting watchTowr Labs) ↗
Aug 17
Attacks
CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch
NIST NVD / CISA KEV ↗
Aug 4
Attacks
CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog
NIST NVD / CISA KEV ↗
Jul 28
Defense
HashiCorp patches CVSS 10.0 cross-tenant credential reuse flaw in Terraform MCP Server
HashiCorp ↗
Jul 27
Defense
NIST opens comment on a draft threat analysis for AI data centers
NIST ↗
Jul 13
Defense
Orca Security report finds 99.9% of fixable AI-package vulnerabilities remain unpatched
Orca Security / Help Net Security ↗
Assistant prompt-injection exfiltration
11
Sep 24
Sep 24
Attacks
A poisoned sales lead was enough to make Salesforce's agent hand over CRM data with no click
Zenity Labs ↗
Sep 16
Attacks
One extension can hand a prompt straight to the built-in agents of five browsers
Forever Security ↗
Sep 8
Defense
A shared internal package service let one ChatGPT account quietly task another account's session
Check Point Research ↗
Sep 3
Attacks
Microsoft says a prompt-injection technique has crossed over into large-scale phishing filter evasion
Microsoft ↗
Aug 20
Defense
Researchers show encrypted 'context injection' turns Grok and Gemini into zero-click data-theft channels
Adversa AI ↗
Aug 18
Defense
Varonis discloses CoSnitch, a one-click Microsoft Copilot Personal flaw chain that could silently exfiltrate data from connected apps
Varonis Threat Labs ↗
Aug 8
Defense
Researchers show Atlassian's Rovo AI assistant could be tricked into exfiltrating Jira and Confluence data
Varonis / PromptArmor (via The Hacker News) ↗
Jul 30
Defense
Microsoft ships Defender prompt injection protection in preview and unified agent security for Agent 365
Microsoft Security Blog ↗
Jul 24
Attacks
"AgentForger" flaw let one phishing link stand up a persistent agent with a victim's access
The Hacker News ↗
Jul 7
Defense
One permission was enough to plant persistent code inside Google Dialogflow CX agents
Varonis Threat Labs ↗
Jul 2
Attacks
Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents
Zscaler ThreatLabz ↗
Agent supply chain
22
Sep 23
Sep 23
Attacks
Compromised AI-memory packages shipped an implant that copies itself wherever the stolen tokens reach
SafeDep ↗
Sep 18
Attacks
CrowdStrike assesses with high confidence that the PhantomRaven npm stealer was written with an LLM
The Hacker News (reporting CrowdStrike) ↗
Sep 17
Attacks
A plugin's pinned commit can be swapped for attacker code in four AI coding agents
AIR Security ↗
Sep 2
Defense
A malicious agent skill steered decisions 81% of the time while still doing its advertised job
arXiv:2609.02564 (Li et al.) ↗
Sep 1
Attacks
A repository's own git config makes seven AI coding agents run attacker code before any prompt
Manifold Security ↗
Sep 1
Defense
The Agent Control Standard is donated to OWASP's GenAI Security Project
OWASP GenAI Security Project ↗
Aug 21
Attacks
Trojanized npm packages deliver RedC2 4.0, a post-exploitation framework with an LLM-driven command layer
The Hacker News (reporting Trend Micro / TrendAI) ↗
Aug 20
Attacks
Poisoned Rust crates ran a backdoor at compile time, on infrastructure Wiz ties to North Korean campaigns
Wiz ↗
Aug 19
Attacks
Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer
Trellix Advanced Research Center ↗
Aug 18
Defense
A malicious GitHub issue chained through Gemini CLI to Editor access on a Google Cloud project
Pillar Security ↗
Aug 12
Attacks
A malicious MCP server turns hostile only after an agent's third tool call
Pillar Security ↗
Aug 9
Attacks
Poisoned observability logs drive AI coding agents, with a sandbox escape patched before disclosure
Tenet Security ↗
Aug 4
Attacks
npm worm in keyv and cacheable namespaces steals AI coding-tool credentials and persists via Claude Code and VS Code hooks
Wiz ↗
Aug 4
Defense
Pillar Security shows a malicious GitHub issue could hijack Google's ADK triage agent to run code as a privileged agent
Pillar Security (via The Hacker News) ↗
Aug 3
Defense
CISA open source software guidance tells organisations to treat opaque open-weight AI models as proprietary software
Help Net Security ↗
Jul 30
Defense
Mandiant records a 1,444% rise in detected malicious open-source packages and names the crews behind two campaigns
Google Cloud / Mandiant ↗
Jul 30
Defense
One malicious agent skill got past all eight open-source skill scanners tested
Adversa AI ↗
Jul 29
Defense
Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance
CISA / NSA / FBI and international partners ↗
Jul 20
Attacks
"FakeGit" weaponizes ~7,600 repos against coding agents
The Hacker News ↗
Jul 20
Attacks
Pillar Security reports sandbox escapes in four AI coding agents, triggered by content inside a repository
Pillar Security ↗
Jul 9
Defense
Agent skill metadata fields can suppress permission prompts and hide a skill from the user
HiddenLayer ↗
Jul 8
Attacks
ESET examined nearly 900,000 AI agent skills and found thousands outright malicious
ESET ↗
Model-access abuse
10
Sep 23
Sep 23
Attacks
A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first
ThreatDown ↗
Sep 22
Attacks
Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it
Team Cymru ↗
Sep 10
Attacks
An actor turned an AI vendor's evaluation sandbox into a source of production API keys
Anthropic ↗
Sep 1
Attacks
Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials
VulnCheck (via The Hacker News) ↗
Aug 31
Attacks
Anthropic tells Claude users that commodity infostealers hijacked their sessions and drained paid usage
Anthropic (via SecurityWeek) ↗
Aug 31
Attacks
Scanners forged AI crawler identities to hunt for exposed credentials
GreyNoise (via Help Net Security) ↗
Aug 31
Attacks
METR discloses two intrusions against itself, including about $600,000 of model credits consumed
METR ↗
Aug 6
Attacks
Unit 42 documents stolen AI API keys resold through proxy transfer stations, with about a million dollars billed before containment
Palo Alto Networks Unit 42 ↗
Aug 4
Attacks
Okta documents gray-market services reselling frontier-model access — and reading every prompt that passes through
Okta Threat Intelligence ↗
Aug 3
Policy
Five Senate Democrats demand a published framework for restricting access to US AI models
Office of Sen. Kirsten Gillibrand ↗
Distillation as exfiltration
5
Sep 16
Sep 22
Attacks
Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it
Team Cymru ↗
Sep 16
Policy
The Chinese Communist Party's own newspaper rejects the US distillation allegations and warns of countermeasures
People's Daily (via South China Morning Post) ↗
Sep 10
Attacks
Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude
Anthropic (via The Hacker News) ↗
Sep 8
Attacks
NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models
NSA / CISA / FBI ↗
Aug 5
Policy
The BLADE Act would sanction foreign entities that extract US models through unauthorized access
Office of Sen. Bill Hagerty ↗
Defeating the AI defender
9
Sep 10
Sep 10
Defense
A payload wrapped in ordinary prose passed four guardrail models and was acted on by the model behind them
Check Point Research ↗
Sep 7
Attacks
A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components
SecurityWeek ↗
Aug 31
Attacks
Malware carries a planted prompt about building a nuclear weapon to stop AI tools analysing it
ESET (via The Hacker News) ↗
Aug 28
Defense
Unit 42 reports that a few dozen neurons control an aligned model's safety refusal behaviour
Palo Alto Networks Unit 42 ↗
Aug 3
Capability
Preprint reports a multi-agent framework evading all seven commercial endpoint security products it was tested against
arXiv preprint 2608.01639 ↗
Aug 1
Defense
Preprint reports rewriting only an agent's reasoning drops a chain-of-thought monitor's catch rate from about 95% to under 11%
arXiv preprint 2608.00583 ↗
Jul 30
Defense
One malicious agent skill got past all eight open-source skill scanners tested
Adversa AI ↗
Jul 23
Defense
UK AI Security Institute's control red team reports vulnerabilities in every version of an Anthropic agent monitor it tested
UK AI Security Institute ↗
Jul 8
Defense
The best model judge gating an offensive agent's tool calls still falls short of human graders
Dreadnode / arXiv:2607.07774 ↗
Items, newest week first
Week of Sep 28
1
Sep 28
Defense
NVIDIA puts agent policy enforcement on a separate chip from the agent
Week of Sep 21
5
Sep 25
Capability
OpenAI says prompt injections that copy themselves into the agent's next output exist in its internal systems
Sep 24
Attacks
A poisoned sales lead was enough to make Salesforce's agent hand over CRM data with no click
Sep 23
Attacks
A Docker botnet installs an off-the-shelf AI agent and tells it to take AI API keys first
Sep 23
Attacks
Compromised AI-memory packages shipped an implant that copies itself wherever the stolen tokens reach
Sep 22
Attacks
Team Cymru maps the relay layer that routes Chinese traffic into US frontier models, and puts a number on it
Week of Sep 14
6
Sep 18
Attacks
CrowdStrike assesses with high confidence that the PhantomRaven npm stealer was written with an LLM
Sep 17
Attacks
A plugin's pinned commit can be swapped for attacker code in four AI coding agents
Sep 17
Defense
A scan of public MCP configuration files finds one credential in eight hardcoded
Sep 16
Policy
The Chinese Communist Party's own newspaper rejects the US distillation allegations and warns of countermeasures
Sep 16
Capability
A coding agent fine-tuned and redeployed the model it was running on, without being told to
Sep 16
Attacks
One extension can hand a prompt straight to the built-in agents of five browsers
Week of Sep 7
10
Sep 11
Attacks
A maximum-severity GitLab flaw drew in-the-wild probes the day it was patched, beside a critical flaw in its AI assistant
Sep 11
Defense
Another unauthenticated code-execution flaw is published against the SGLang inference server
Sep 11
Defense
A census of self-hosted AI infrastructure counts 36,769 reachable endpoints and almost none behind a login
Sep 10
Attacks
An actor turned an AI vendor's evaluation sandbox into a source of production API keys
Sep 10
Attacks
Anthropic names seven China-based AI companies it says ran industrial-scale distillation against Claude
Sep 10
Defense
A payload wrapped in ordinary prose passed four guardrail models and was acted on by the model behind them
Sep 8
Attacks
NSA, CISA and FBI name six China-based AI companies running industrial-scale distillation campaigns against US frontier models
Sep 8
Defense
A shared internal package service let one ChatGPT account quietly task another account's session
Sep 8
Defense
A flaw in DeepSeek's agent harness let a sandboxed agent turn its own confinement off with one command
Sep 7
Attacks
A researcher publishes proof-of-concept zero-day exploits against CrowdStrike Falcon, Avast and Nvidia components
Week of Aug 31
11
Sep 3
Attacks
Microsoft says a prompt-injection technique has crossed over into large-scale phishing filter evasion
Sep 2
Attacks
CISA adds an authentication bypass in the LiteLLM AI gateway to its exploited-vulnerabilities catalog
Sep 2
Defense
Two chained flaws let unauthenticated callers reach data through Grafana's MCP server
Sep 2
Defense
A malicious agent skill steered decisions 81% of the time while still doing its advertised job
Sep 1
Attacks
Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials
Sep 1
Attacks
A repository's own git config makes seven AI coding agents run attacker code before any prompt
Sep 1
Defense
The Agent Control Standard is donated to OWASP's GenAI Security Project
Aug 31
Attacks
Malware carries a planted prompt about building a nuclear weapon to stop AI tools analysing it
Aug 31
Attacks
Anthropic tells Claude users that commodity infostealers hijacked their sessions and drained paid usage
Aug 31
Attacks
METR discloses two intrusions against itself, including about $600,000 of model credits consumed
Aug 31
Attacks
Scanners forged AI crawler identities to hunt for exposed credentials
Week of Aug 24
8
Aug 28
Defense
Unit 42 reports that a few dozen neurons control an aligned model's safety refusal behaviour
Aug 28
Attacks
Metasploit ships public exploit modules for two AI application platforms
Aug 28
Attacks
VulnCheck logs more than 15,000 successful exploitation attempts against Langflow
Aug 27
Attacks
Wiz honeypots record attackers exploiting MCP servers and self-hosted AI stacks
Aug 27
Defense
ServiceNow patches three flaws rated CVSS 10.0 in its AI Platform
Aug 26
Attacks
Microsoft reports attackers compromising self-hosted AI gateways and orchestration platforms for credentials and cryptomining
Aug 25
Defense
Oasis Security discloses a NemoClaw flaw that lets a malicious webpage poison a developer's local AI model
Aug 25
Defense
RAND publishes a 262-control framework for securing AI model weights at security level 3
Week of Aug 17
8
Aug 21
Attacks
Trojanized npm packages deliver RedC2 4.0, a post-exploitation framework with an LLM-driven command layer
Aug 20
Defense
Researchers show encrypted 'context injection' turns Grok and Gemini into zero-click data-theft channels
Aug 20
Attacks
Poisoned Rust crates ran a backdoor at compile time, on infrastructure Wiz ties to North Korean campaigns
Aug 19
Attacks
Trellix counts more than 350 malicious skills in the OpenClaw agent registry delivering a credential stealer
Aug 18
Defense
Varonis discloses CoSnitch, a one-click Microsoft Copilot Personal flaw chain that could silently exfiltrate data from connected apps
Aug 18
Attacks
Attackers exploit a critical SSRF flaw in the MLflow AI platform to steal cloud credentials
Aug 18
Defense
A malicious GitHub issue chained through Gemini CLI to Editor access on a Google Cloud project
Aug 17
Attacks
CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch
Week of Aug 10
1
Aug 12
Attacks
A malicious MCP server turns hostile only after an agent's third tool call
Week of Aug 3
11
Aug 9
Attacks
Poisoned observability logs drive AI coding agents, with a sandbox escape patched before disclosure
Aug 8
Defense
Researchers show Atlassian's Rovo AI assistant could be tricked into exfiltrating Jira and Confluence data
Aug 6
Attacks
Unit 42 documents stolen AI API keys resold through proxy transfer stations, with about a million dollars billed before containment
Aug 5
Policy
The BLADE Act would sanction foreign entities that extract US models through unauthorized access
Aug 4
Attacks
CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog
Aug 4
Defense
Pillar Security shows a malicious GitHub issue could hijack Google's ADK triage agent to run code as a privileged agent
Aug 4
Attacks
npm worm in keyv and cacheable namespaces steals AI coding-tool credentials and persists via Claude Code and VS Code hooks
Aug 4
Attacks
Okta documents gray-market services reselling frontier-model access — and reading every prompt that passes through
Aug 3
Defense
CISA open source software guidance tells organisations to treat opaque open-weight AI models as proprietary software
Aug 3
Policy
Five Senate Democrats demand a published framework for restricting access to US AI models
Aug 3
Capability
Preprint reports a multi-agent framework evading all seven commercial endpoint security products it was tested against
Week of Jul 27
7
Aug 1
Defense
Preprint reports rewriting only an agent's reasoning drops a chain-of-thought monitor's catch rate from about 95% to under 11%
Jul 30
Defense
Microsoft ships Defender prompt injection protection in preview and unified agent security for Agent 365
Jul 30
Defense
One malicious agent skill got past all eight open-source skill scanners tested
Jul 30
Defense
Mandiant records a 1,444% rise in detected malicious open-source packages and names the crews behind two campaigns
Jul 29
Defense
Seventeen agencies update the minimum elements for a software bill of materials, and leave AI systems to separate guidance
Jul 28
Defense
HashiCorp patches CVSS 10.0 cross-tenant credential reuse flaw in Terraform MCP Server
Jul 27
Defense
NIST opens comment on a draft threat analysis for AI data centers
Week of Jul 20
4
Jul 24
Attacks
"AgentForger" flaw let one phishing link stand up a persistent agent with a victim's access
Jul 23
Defense
UK AI Security Institute's control red team reports vulnerabilities in every version of an Anthropic agent monitor it tested
Jul 20
Attacks
"FakeGit" weaponizes ~7,600 repos against coding agents
Jul 20
Attacks
Pillar Security reports sandbox escapes in four AI coding agents, triggered by content inside a repository
Week of Jul 13
1
Jul 13
Defense
Orca Security report finds 99.9% of fixable AI-package vulnerabilities remain unpatched
Week of Jul 6
4
Jul 9
Defense
Agent skill metadata fields can suppress permission prompts and hide a skill from the user
Jul 8
Attacks
ESET examined nearly 900,000 AI agent skills and found thousands outright malicious
Jul 8
Defense
The best model judge gating an offensive agent's tool calls still falls short of human graders
Jul 7
Defense
One permission was enough to plant persistent code inside Google Dialogflow CX agents
Week of Jun 29
1
Jul 2
Attacks
Zscaler ThreatLabz reports web content in the wild carrying indirect prompt injections aimed at autonomous browsing AI agents