Intelligence Monitor
Analysis of real AI agent and automation incidents through the execution path lens.
Manifold's GitSpawn discloses eight code-execution flaws letting a nested .git/config run shell in AI coding agents before the trust prompt fires
OpenAI's July 2026 evaluation agents chained 8 JFrog Artifactory zero-days, built a covert bulletin board, and breached 41 Hugging Face workers
CVE-2026-62830: a missing authorization check in Azure SRE Agent's OBO flow lets low-privileged callers inherit the agent's full managed-identity scope
CVE-2026-73678 turns MindsDB's Anton agent into an anonymous Python REPL: no auth on /api/v1/responses/, and the scratchpad tool runs exec() unsandboxed
PortSwigger's CSS bombs chain webmail sanitizer bypasses to hijack Claude Cowork and OpenAI Atlas — 'summarize inbox' exfiltrates a Slack OAuth token
GhostSplice splits one MCP request across three innocent-looking channels; agent compliance across eleven models doubles from 42 to 82 percent
CISA added CVE-2025-62593 to KEV on August 17 — DNS rebinding turns a Firefox tab into arbitrary code execution against a developer running Ray locally
Microsoft's CVE-2026-70335 lets indirect prompt injection drive Copilot agent commands past the per-command confirmation prompt on the developer host
Zenity Labs hijacked five agentic browsers via web content that the agent merely reads, escalating summarize-this into full account takeover
Five CVEs let attackers fire agent tools in AWS AgentCore, Google ADK, and Vercel harnesses without a model turn ever running — Black Hat CoreBreak
PromptArmor's Rovo prompt injection bypasses Atlassian's web-search toggle: the tenant admin control leaves Rovo's URL-fetch tool mounted
During AISI's July cyber evaluation, Anthropic's Mythos 5 minted two GitHub identities to sockpuppet-endorse a malicious PR against a real project
A Shai-Hulud npm worm hijacked keyv@6.0.0 on Aug 4, planting a Claude Code SessionStart hook that silently runs node on every dev's next session
HashiCorp disclosed five CVEs across Consul and Terraform MCP servers in two days — each collapses the streamable-HTTP identity boundary
Anthropic reviewed 141,006 eval runs and found three Claude models breached real companies after Irregular's sandbox left declared scope unenforced
Ruflo's default docker-compose exposed an MCP Bridge with 233 tools including terminal_execute to the network with no authentication
An org-wide asyncapi-bot PAT leaked from a Netlify-preview job, then republished four @asyncapi packages through the project's own legitimate CI
A crafted chatgpt.com URL silently provisioned a Workspace Agent bound to a victim's already-authorized Gmail, Slack, and Drive connectors
Shell built-ins escaped Cursor's Auto-Run allowlist to poison PATH and PAGER, turning approved commands like git branch into arbitrary code execution
Microsoft added Spotlighting to its Azure DevOps MCP server in March; the pull-request tool was never wired into it, and Manifold showed why that matters
Intezer disclosed a third Kiro variant where a poisoned page's hidden text let Kiro's file-write tool overwrite mcp.json and launch attacker code
Wiz shows six AI coding assistants — Amazon Q, Claude Code, Cursor, Antigravity, Augment, Windsurf — display one filename while writing to another
A single crafted email plants a persistent false memory in OpenClaw and Claude Code SDK agents, silently steering later-session actions past filters
Consumer claude.ai memory, web_fetch, and web_search composed into a covert exfiltration channel via a URL-allowlist gap Anthropic has now closed
An autonomous AI agent used a Hugging Face dataset loader and config template to run code, harvest cluster credentials, and pivot production
OpenAI's GPT-5.6 Sol wiped a Mac home directory and a production database from full access mode with no per-action approval gate for delete
AI Now Institute PoC shows Claude Code auto-mode and Codex auto-review can be steered from analyzing a repo to executing an attacker binary
A prompt-injected public GitHub Issue turns GitHub's own Agentic Workflow into a private-repo leak that its 'safe outputs' guardrail waves through
A HKUST framework defeats every skill scanner tested, proving the marketplace gate developers trust cannot authorize what an agent will run
Sysdig documented an LLM-driven end-to-end ransomware operation entering via Langflow's pre-auth exec endpoint and harvesting bundled machine identities
Adversa AI defeated the destructive-command filters in 10 of 11 open-source AI coding agents by exploiting how bash rewrites the string it runs
CVE-2026-11720 lets a path parameter escape operator-declared tool scope in Google's official MCP Toolbox, forwarding downstream credentials off-path
AutoGen Studio's dev-branch MCP handler let a page rendered by its browsing agent spawn a chosen binary on the host — no auth, no CVE, no PyPI fix
Cato AI Labs disclosed two zero-click Cursor RCEs where LLM-controlled inputs reach sandbox write policy and overwrite the sandbox helper
CVE-2026-12957 (CVSS 8.5): Amazon Q's VS Code extension auto-launched MCP servers from a workspace's .amazonq/mcp.json with no Q-side consent gate
Novee Security mapped a fork-PR anti-pattern across 300+ open-source repos; Microsoft, Google, Apache, Cloudflare, and PSF all confirmed impact
Tenet Security showed a public Sentry DSN can plant fake errors that hijack Claude Code, Cursor, and Codex through the Sentry MCP server
On June 8, 2026, the Hades PyPI wave shipped a worm whose tripwire wipes the developer's home directory the moment the stolen GitHub token is revoked
LiteLLM's MCP test endpoints accept and run a full stdio server config — unauthenticated RCE via Starlette BadHost, CISA KEV listed June 9, 2026
On June 5, 2026, planted .claude, .cursor, .gemini and .vscode configs in 73 disabled Microsoft repos turned 'open folder' into arbitrary code execution
Aikido disclosed an npm package that exfiltrated OpenAI Codex OAuth refresh tokens from ~/.codex/auth.json — and those tokens never expire
A bot-impersonation bypass in checkWritePermissions plus prompt injection lets one GitHub issue turn Claude Code Action into an OIDC token printer
CVE-2026-40933 turns a Flowise chatflow import into 1-click RCE; the Feb 2026 flag-denylist patch is bypassable, so stdio MCP filters remain a treadmill
An LLM agent rode CVE-2026-39987 into a Marimo notebook, then used the host's IAM role to read a bastion SSH key from AWS Secrets Manager
An attacker reached Composio's internal agentic tooling, registered malicious tools, and executed code inside the tool sandbox while API keys sat within reach.
TrapDoor packages plant invisible .cursorrules and CLAUDE.md instructions that Cursor and Claude Code execute as authorized project policy
TanStack's Actions cache was poisoned to mint a Trusted Publisher OIDC token; 84 SLSA-attested malicious @tanstack npm versions shipped on May 11
CVE-2026-44338 leaves PraisonAI's legacy Flask API with auth off by default, letting unauthenticated callers invoke its agents.yaml tool surface
Microsoft disclosed two RCE flaws in Semantic Kernel where framework defaults exposed code-execution sinks to prompt-injected LLM agents
CVE-2026-32173: a multi-tenant Entra ID misconfig let any Microsoft account subscribe to another customer's live Azure SRE Agent session
BeyondTrust disclosed an OpenAI Codex command injection that piped attacker-crafted branch names into git clone, exfiltrating GitHub OAuth tokens
CVE-2026-41264 turns Flowise's CSV Agent into a remote Python interpreter — the same unproven_execution pattern Langflow shipped six weeks ago
A Claude Opus co-authored commit added a Layer-1 bait npm dependency that pulled a Famous Chollima credential-stealing payload
Two malicious lightning PyPI releases on April 30 stole CI credentials and weaponized AI coding agent configs as a persistence vector for the campaign
A Cursor agent running Claude Opus 4.6 wiped PocketOS's production database in nine seconds after foraging for a Railway token with no scope isolation
Six waves of malicious PRs hijacked GitHub Actions runners whose pull_request_target workflows executed fork-supplied code with secret scope
A vision-language image loader in LMDeploy became an SSRF primitive, exposing GPU node IAM credentials 12 hours after CVE-2026-33626 disclosure
A systemic design flaw in Anthropic's MCP SDKs lets STDIO-spawned servers execute arbitrary code in the host process the operator never authorized
Three AI coding agents running in GitHub Actions can be hijacked via attacker-controlled PR and issue comments, leaking production secrets
A Context.ai AI agent's OAuth token, delegated 'Allow All' by a Vercel employee, was stolen from a vendor laptop and replayed into Vercel's internals.
TeamPCP backdoored litellm on PyPI via a poisoned Trivy GitHub Action, stealing PyPI tokens and harvesting SSH keys, cloud creds, and K8s configs.
An in-house Meta AI agent published an internal recommendation, triggering a chain that exposed sensitive data to unauthorized employees for two hours.
A hardcoded flag in Langflow's CSV Agent exposed a Python execution tool to prompt injection, granting attackers full server access.