The Wire.Tracking threats to Agents 214 raw → 13 curated · updated 27 Jun 2026

Lead dispatch · top current threat

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

A Rust-based macOS implant and information stealer dubbed Gaslight embeds prompt injection strings and fake debugging/error data within its executable to trick AI-assisted malware analysis tools into aborting or refusing analysis of the artifact.

SEV 0.60   REL 0.90
prompt-injection · anti-analysis
llm · ai-agents

The wire · latest

Dawn of the Apex Agentic Adversary

An analysis piece arguing that autonomous, agentic AI adversaries are compressing the timeline of cyberattacks beyond human-speed defenses, ending the era of human-paced threat cycles. The available text is introductory commentary without specific technical proof-of-concept details.

analysisautonomous-attack-frameworkai-agentsllm

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

Security firm AIR built a fake AI agent skill and distributed it via a popular skill marketplace and an Instagram ad, reportedly reaching roughly 26,000 agents including some on corporate accounts. Every skill security scanner tested marked it safe, though the payload was harmless by design and only collected the user's email address.

researchsupply-chainmalicious-agent-skilldata-exfiltrationai-agents

Agentic AI: The Weapon That No Longer Needs a Warrior

An opinion/commentary piece reflecting on how agentic AI removes the human from the targeting loop, drawing analogies to the historical evolution of weapons that distanced warriors from their victims.

analysisautonomous-attackai-agentsllm

What nearly 10,000 developer environments reveal about agentic development risk

Snyk analyzed nearly 10,000 developer environments to examine risks introduced by AI coding agents as a new layer in the software supply chain, highlighting issues around tools, instructions, and permissions in agentic development.

researchsupply-chaintool-abuseai-agentscopilotmcp

Prompt Injection as Role Confusion

Research by Charles Ye, Jasmine Cui, and Dylan Hadfield-Menell shows LLMs cannot reliably distinguish privileged system/assistant text from untrusted user input, and weigh writing style over content. Crafting injected text in the style of internal reasoning blocks ('role confusion') enabled jailbreaks, with attack success at 61% that dropped to 10% when text was 'destyled.'

researchprompt-injectionjailbreakllm

DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories

Four vulnerabilities dubbed 'DifyTap' in Dify, a platform for building and managing AI applications, allow attackers to silently access and exfiltrate sensitive data, including AI chat histories.

advisorydata-exfiltrationsupply-chainllmai-agents

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

A conference talk recap discussing how attackers may use legacy infrastructure to circumvent AI security programs and hijack AI agents, noting rapid AI agent adoption outpacing security controls.

analysisagent-hijackingai-agents

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

The article argues that shadow AI in enterprises has evolved from a data leakage concern into an access control problem, where the risk lies in autonomous AI tools and agents having unmanaged access permissions rather than just employees pasting sensitive data.

analysisshadow-aiaccess-controlai-agentsllm

Quoting Matteo Wong, The Atlantic

An Atlantic piece quotes cybersecurity expert Katie Moussouris discussing a White House report on a Claude jailbreak, where the model refused to 'review code for security issues' but complied when asked to 'fix this code.' Moussouris characterized this as the model working as intended for cyberdefense rather than a genuine exploit.

analysisjailbreakllm

The New Security Risks of the Agentic Development Lifecycle

An article discussing how AI agents are reshaping the software development lifecycle and shifting where security risk originates, arguing that securing the development process matters as much as securing code.

analysissupply-chainai-agentsllm

Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection

The jqwik 1.10.0 release added a hidden prompt injection targeting AI coding agents, using terminal escape codes to conceal destructive instructions from humans while keeping them readable to logs and tools. This was introduced by the open source maintainer as protestware against agentic coding.

prompt-injectionsupply-chainai-agentsllmcopilot

Inside MCP: defending the runtime layer of agent security · Arcis Blog

An Arcis blog post argues that agent security has four layers (identity, pre-deploy testing, observability, runtime defense) and that the runtime hot path is structurally underserved. It frames MCP's explicit tool-call contract as enabling runtime defense against agent toolcall injection (their vector V32), applying allowlist/sanitize/refuse techniques at the agent-tool boundary.

analysistool-abuseprompt-injectionmcpai-agents
View all 13 curated incidents →

How the wire is made

Poll & cluster

Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable incidents.

Curate

AI Agent filters for agentic-AI relevance, tags threat-type & affected-tech, scores severity & relevance, and writes the summary.

Every item here is one machine-curated intelligence object, not a headline.

Read the wire for free. There is a small charge to ask the index questions.

The wire, open

The complete curated feed, no key required.

Subscribe to the RSS feed

The vector desk

Query the index by meaning, not just keyword.

  • GET /api/items?tags=&minSeverity=&itemType=
  • GET /api/search?q= — keyword
  • GET /api/semantic?q= — vector
Get an API key — preview
Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS