First reported · updated · 2 reports threatdown.com
Lead dispatch
First reported secmate.dev
Mistral Vibe Permission Bypass and Arbitrary Code Execution
SecMate disclosed two flaws in Mistral Vibe 2.25.0 (CVE-2026-87987 and CVE-2026-87984) where the coding agent's Bash tool used Tree-sitter to extract a reduced representation of a shell command for its permission allowlist, then executed the original untouched string. Hostile repository content could lead the model to emit a crafted tool call (e.g. an environment assignment prefixing an allowlisted command) that the permission parser classified as read-only, bypassing the approval prompt and enabling arbitrary code execution and reads/writes outside the authorized workspace. Mistral released Vibe 2.25.4 on September 12, 2026.permission-bypass · arbitrary-code-execution · command-injection · indirect-prompt-injection · data-exfiltration · tool-abuse
ai-agents · coding-agent · llm
The wire · latest
First reported daily.dev
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
A guardrail-free AI platform called 'Kriminal' markets itself to cybercriminals, offering social-engineering personas, exploit assistance, uncensored image generation, OSINT scanning, and crypto tracing via cryptocurrency subscriptions starting at $12.99/month. ThreatDown (Malwarebytes) research found the service is not proprietary but stitches together off-the-shelf components — Grok for inference, Claude for long-context tasks, Llama via OpenRouter, Tavily for search, and Google Cloud/Cloudflare for hosting, with NowPayments handling KYC-free crypto checkout — making it resilient to takedown since no single vendor sees the whole picture. Details →First reported threatdown.com
How Grok unknowingly powers cybercrime
ThreatDown (Malwarebytes) research analyzed 'Kriminal,' a clearnet-indexed, crypto-paid 'no filters, no guardrails' AI service marketed to cybercriminals for OSINT dossiers, exploit development, on-chain tracing, and social-engineering personas starting at $12.99/month. Analysis of Kriminal's own code found it is not an original model but a reseller wrapper around Grok, contradicting its claim to be a purpose-built criminal AI. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector