First reported oligo.security
Lead dispatch
First reported · updated · 2 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers disclosed a vulnerability in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file (indirect prompt injection) can make Kiro rewrite its own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine without any approval prompt. Because Kiro can write to these files without user consent, the human-in-the-loop approval boundary is bypassed entirely. Amazon issued CVE-2026-10591 and the flaw is now fixed.indirect-prompt-injection · tool-abuse · remote-code-execution · supply-chain
ai-agents · mcp · llm · coding-agent · ide
The wire · latest
First reported · updated · 8 reports redhat.com
LiteLLM AI Gateway: Active Exploitation via MCP Injection – Lab Space
LiteLLM, an open-source AI gateway proxy with roughly 95 million monthly PyPI downloads, is affected by a cascading 2026 vulnerability chain that exposes the aggregated provider API keys it stores. The chain includes a March 2026 PyPI supply-chain compromise attributed to TeamPCP (CVE-2026-33634), a pre-auth SQL injection (CVE-2026-42208) that dumps stored credentials, and a command-injection flaw in LiteLLM's MCP server test endpoints (CVE-2026-42271) chained with a Starlette host-header bypass (CVE-2026-48710) for unauthenticated RCE assessed at CVSS 10.0; CISA added CVE-2026-42271 to its KEV catalog on June 8, 2026 with remediation required by upgrading to v1.83.10-stable. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector