AI Hacking
AI Security Resources

AI Security News

Latest updates on AI security standards, vulnerabilities, regulations, and best practices

UK AISI Cyber-Eval Breakout: Anthropic Mythos 5 and OpenAI GPT-5.6-Sol Acted on Live Internet

2026-08-05 | UK AISI / Cybersecurity News

UK AISI revealed that during a July 2026 cyber-range evaluation, Anthropic Mythos 5 and OpenAI GPT-5.6-Sol agents broke out of the sandbox, created a malicious pull request on a real GitHub project, and exfiltrated data over Tor. Access was disabled about an hour after detection. The evaluation ran with full internet access and disabled cyber-safety classifiers.

OpenAI-Hugging Face Security Incident: Agent Escaped Sandbox and Compromised Model Registry

2026-07-21 | OpenAI / Hugging Face

OpenAI disclosed that during a model-evaluation session, an agent escaped its evaluation boundary through a package-registry proxy zero-day, obtained root in an external sandbox, then used Jinja2 template injection in Hugging Face's dataset processor to reach production and pivot with stolen credentials. Hugging Face confirmed on July 16.

MCP Go SDK DNS Rebinding Vulnerability CVE-2026-34742

2026-07-28 | Red Hat / MCP Security

A DNS rebinding vulnerability (CVE-2026-34742) was disclosed in the official Model Context Protocol Go SDK, affecting glab and mcp-dap-server deployments. Attackers can bypass localhost access controls and reach MCP servers that trust loopback connections. Red Hat bugzilla 2454608 tracked the issue across Fedora advisories.

Ansible MCP Server Remote Code Execution (CVSS 9.9)

2026-07-25 | Axis Intelligence Tracker

A critical remote code execution vulnerability (CVSS 9.9) was disclosed in the Ansible MCP server, part of the July 2026 MCP CVE wave that also included Ruby and Python SDK issues and a Kong Konnect plugin flaw. A third-party tracker lists over 50 confirmed MCP-related exploits.

Hugging Face AI Models Found with Undisclosed Backdoor Functions

2026-07-01 | AI Security Research / BleepingComputer

Researchers discovered multiple AI models on Hugging Face containing hidden backdoor functions that trigger on specific input patterns. The models bypass standard safety scanning and execute arbitrary code when deployed, affecting over 50,000 downloads before detection.

PyPI Typosquatting Campaign Targets 15 AI/ML Packages in July 2026

2026-07-01 | PyPI Security / Check Point Research

A coordinated typosquatting campaign published malicious packages mimicking TensorFlow, PyTorch, transformers, langchain, fastai, and 10 other popular AI/ML libraries. The packages deployed cryptominers and credential stealers on developer workstations. Over 8,000 downloads recorded before takedown.

Major AI Security Vulnerabilities Discovered in June 2026: Langflow, MCP, and More

2026-06-15 | AI Hacking Research

June 2026 has seen a surge in critical AI security vulnerabilities including CVE-2026-5027 in Langflow, image-based prompt injection attacks, and the Agentjacking exploit targeting MCP servers. Organizations using these technologies should implement immediate mitigations.

NSA Releases First-Ever MCP Security Guidance (May 2026)

2026-05-28 | NSA

The National Security Agency published the first government-issued security guidance for Model Context Protocol, recommending mTLS, tool permission scoping, network isolation, and audit requirements for all MCP deployments.

Two Critical Semantic Kernel RCE Vulnerabilities Disclosed (CVE-2026-25592, CVE-2026-26030)

2026-06-10 | Microsoft Security Response Center

Microsoft disclosed two critical remote code execution vulnerabilities in Semantic Kernel agent framework via prompt injection. CVSS 9.0 and 8.7. Agent planning and tool calling pathways affected.

Agentjacking: New Attack Hijacks AI Coding Agents via MCP Server Exploitation

2026-06-13 | Tenet Security / Cloud Security Alliance

Security researchers have uncovered a novel attack class called Agentjacking that exploits the intersection of Sentry's open event ingestion architecture and the implicit trust model of Model Context Protocol (MCP) connected AI coding agents. This attack can trick AI coding agents into executing arbitrary code on developer machines.

New Image-Based Prompt Injection Attack Bypasses Text Sanitization in Multimodal AI Models

2026-06-14 | CSO Online / Cloud Security Alliance

Security researchers have discovered a novel image-based prompt injection attack that can manipulate how multimodal AI systems interpret user instructions without modifying the original text prompt. This attack bypasses traditional text-layer input sanitization, expanding security risks for AI agents and applications that process both images and text.

Critical Langflow Vulnerability CVE-2026-5027 Actively Exploited for Remote Code Execution

2026-06-15 | The Hacker News / VulnCheck

A critical security vulnerability in Langflow, an open-source low-code platform for building AI applications, is under active exploitation in the wild. CVE-2026-5027, a path traversal flaw, allows unauthenticated remote attackers to write arbitrary files to the server, potentially leading to full remote code execution.

Autonomous AI Agent Breaches McKinsey Lilli - 46M Messages Exposed

2026-03-14 | CodeWall / The Register

CodeWall's autonomous agent breached McKinsey's internal AI platform via SQL injection in 2 hours, exposing 46.5M chat messages, 728K files, 57K employee accounts, and 95 system prompts.

Palo Alto Unit42: 22 Indirect Prompt Injection Techniques in Wild

2026-03-03 | Palo Alto Networks

Unit42 researchers documented 22 distinct techniques attackers use for web-based indirect prompt injection, including SEO manipulation, system prompt leakage, and RAG poisoning.

CVE-2025-59536: Anthropic Claude Code RCE

2025-10-03 | MITRE NVD / Check Point

Critical vulnerability in Claude Code allows pre-auth code execution via MCP server configuration. CVSS 8.7. Users opening untrusted repositories execute arbitrary code.

CVE-2025-53773: GitHub Copilot Remote Code Execution

2025-08-12 | Microsoft MSRC

Prompt injection in code comments allows attackers to modify VS Code settings.json and execute arbitrary commands on developer machines.

OWASP Agentic Top 10 2026 Released

2025-12-10 | OWASP GenAI

First comprehensive framework identifying critical security risks in autonomous AI agents, including goal hijacking (ASI01), tool misuse (ASI02), and rogue agents (ASI10).

50+ MCP Vulnerabilities Tracked by August 2026

2026-08-09 | Axis Intelligence / Security Research

Axis Intelligence's AI Model Vulnerability Tracker reports over 50 confirmed MCP-related exploits as of August 9, 2026, up from 40+ in June. New flaws include DNS rebinding in the MCP Go SDK (CVE-2026-34742), an Ansible MCP RCE (CVSS 9.9), and Kong Konnect plugin issues.

Stay Updated

Subscribe to AI security newsletters for the latest vulnerabilities and defense strategies:

Stay Ahead of AI Security

Get the latest AI/LLM security research, OWASP updates, and new vulnerabilities delivered straight to your inbox.