Cloudflare Gateway now classifies inspected Streamable HTTP MCP traffic using the MCP-Protocol-Version header, exposes the user and destination in logs and a dashboard, and supports allow or block rules through an MCP-specific selector. The article distinguishes unapproved shadow MCP from direct connections that bypass an approved Portal's controls, and notes blind spots including local stdio, off-network, non-inspected, and otherwise unobserved traffic.
Salesforce’s Paula Goldman argues on the OECD.AI blog that the Hiroshima AI Process Reporting Framework can give organizations a common language for public AI-risk disclosures across jurisdictions and the expanding agentic-AI value chain.
Wiz describes controls for agent-assisted software delivery: inventory models, frameworks, IDE extensions, infrastructure-as-code, and third-party CI actions; map code to deployed resources; run pre-commit checks for secrets and unsafe AI patterns; and expose excessive pipeline permissions and prompt-injection paths.
OWASP roundup of reported GenAI incidents and exploit patterns from Q1 2026. Relevant as a threat-intelligence reference for risk tracking and test-case design.
Google DeepMind’s December 2025 FACTS suite evaluates factual answers under four different information conditions: model knowledge alone, web search, images and supplied documents. Its search track standardizes the retrieval tool across models, while public examples accompany a private held-out evaluation set managed by Kaggle. The combined score averages results across tracks and sets, which can conceal sharply different failure patterns. The release provides a reusable evaluation structure, but benchmark accuracy does not establish factual reliability on a different application’s questions, retrieval system or user population.
Play video
RIG-RAG converts changing cloud configuration data into a typed, security-enriched graph for natural-language investigation and scheduled oversight. The authors report a production AWS deployment supporting 300,000 users, with interactive queries for analysts and curated recurring questions that detect infrastructure drift and expose relationships such as public reachability and identity access.
Microsoft documents two compromised service principals used for Azure discovery, resource destruction and credential collection in activity linked to Storm-3168. The investigation distinguishes successful deletions from failed operations and attempts to remove recovery protections. Although the actor is associated with agentic ransomware reporting, the Azure evidence establishes destructive cloud operations, not a confirmed autonomous decision for every action. Microsoft reports no observed ransom note or confirmed successful data exfiltration in this case.
Play video
Suchet Bargoti demonstrates remotely coordinated drones and explains Skydio’s division of autonomy between aircraft and cloud services. Immediate control stays on the vehicle; cloud models support heavier reasoning, shared maps and tool-based task planning. Fleet observations feed later updates. The talk illustrates how an operator can shift attention between aircraft, while its stated reliability target is not a measured fleet-wide success rate.
Hacktron reports chaining an image-processing flaw with an OpenAI SSO weakness to access employee ChatGPT and Codex accounts. Researchers used Claude with human direction and demonstrated repository access with a harmless pull request; they say they did not read internal code.
OX Research reports that DeepSeek Harness’s local control API could let a sandboxed agent disable its own confinement. The issue affected 0.1.1-rc.2 and earlier; researchers report remediation and a successful retest in 0.1.2-alpha.1.
CISA, NSA and FBI allege industrial-scale extraction of US model capabilities through distributed accounts, proxies and aggregators. Their advisory recommends correlating prompts, usage and account behavior across providers; it distinguishes these alleged campaigns from legitimate model distillation.
CloudSEK and Gambit Security report that an Aurora ransomware affiliate used Cursor for sustained Russian-language attack planning and hands-on exploitation after obtaining credentials or an existing route into victim networks. Recovered infrastructure linked the agent sessions to Active Directory discovery and escalation plans, while the broader intrusion still relied on familiar social engineering, credential theft, lateral movement, defense evasion, exfiltration, and ransomware deployment.
Play video
The NDSS-backed research identifies six inference-time cache attacks across vLLM, SGLang, GPTCache, and related stacks. Weak prefix and image cache keys plus semantic near-match errors can make distinct inputs share cached state, enabling poisoned responses, information leakage, and moderation bypass; the authors provide experimental artifacts and vendor disclosures.
Adversa compares ten shipped or research-stage zero-click agent compromises, including EchoLeak, DuneSlide, TrustFall, ShadowLeak, GeminiJack, and Morris II. The recurring chain is untrusted retrieved content entering model context, an agent applying inherited privileges, and data or code escaping through images, cloud requests, browser navigation, email, or a developer shell.
An Anthropic and EPFL preprint tests self-propagating instructions in sandboxed agent chains whose MEMORY.md and SOUL.md files persist across sessions. Writes to the system-loaded soul file produced most propagation attempts and infected the next agent 55% of the time; all four action payloads survived some 20-hop trials. A one-paragraph warning reduced tested spread to near zero, and the researchers found no successful wild propagation in archived Moltbook data.
Varonis' CoSnitch research combines Copilot Personal's q parameter with an undocumented autorun parameter so one crafted link executes an attacker prompt inside a signed-in session. The prompt can read already authorized mail, calendars, Drive metadata, chat history, and memory, then exfiltrate data through Copilot's URL fetch. A separate web-summarization path could persist attacker instructions in memory. Microsoft patched CVE-2026-24301 on August 18.
Play video
Drawing on nine years of cross-industry ML deployments, Megan Robertson explains why a statistically accurate model can still fail to deliver in production. The session moves beyond offline performance to scoping, organizational failure modes, monitoring, maintainability, and the operational conditions required for a model to keep producing useful results.
A review of nine coding-agent incidents from 2025 and 2026 separates shell, path, and harness failures from constraint decay and excessive permissions, then maps them to concrete controls for identities, filesystems, approvals, verification, logging, and backups.
Before Ruflo 3.16.3, its default Docker Compose deployment bound the MCP bridge to all interfaces without authentication. A reachable attacker could invoke the terminal tool, read model-provider keys and conversations, spawn agents, and poison persistent AgentDB patterns. Noma Labs verified the chain; the patch adds loopback binding, bearer authentication for public exposure, an opt-in terminal tool, authenticated MongoDB, tighter CORS and container defaults, and regression tests.
Hunt.io recovered 585 files and Hermes logs from an exposed staging server used against Thailand's Ministry of Finance. The evidence shows an operator who already had target knowledge and access running Hermes in unattended “YOLO” mode for repetitive post-exploitation enumeration, while also staging Hadoop exploitation scripts and a custom Hades implant; it does not show the agent finding the initial entry point or novel vulnerabilities.
Adversa AI describes DeepJack, a Cursor deeplink weakness in which a crafted cursor:// link can register an attacker-controlled MCP server and hide the command that will execute behind an incomplete installation prompt.
Unit 42 analyzes TuxBot v3 Evolution, a roughly 70%-functional IoT botnet framework with code compiled for 17 architectures. Researchers found raw model reasoning, hallucinated cryptography, and other evidence of unreviewed LLM-generated code in the source.
Play video
Fuzzinglabs researchers explain how threat modeling, file-format fuzzing, and plugin analysis exposed an authentication bypass and memory-corruption issues in Ollama plus command injection in NVIDIA Triton Inference Server's model-configuration pipeline. The Pwn2Own case study also examines RedisAI, ChromaDB, and container-runtime attack surfaces.
OpenAI previews GPT-5.6 Sol, a next-generation model with stronger capabilities in coding, science, and cybersecurity, paired with its most advanced safety stack.