First reported securityweek.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported theregister.com
Anthropic cracks down on hijacked user accounts mining AI tokens
Anthropic is responding to a wave of infostealer malware that steals Claude login credentials, session cookies, and MFA-bypass data to hijack accounts and freeload on victims' paid AI usage (token mining). Anthropic detected attempted API-based token theft, logged affected users out, and removed saved payment methods; the company stresses the malware is ordinary commodity infostealer activity unrelated to Claude itself and not agentic AI malware. Details →First reported nhimg.org
AI-driven browser prompt injection exposes account takeover gaps
NHIMG summarizes Fingerprint's analysis of the Comet AI-powered browser incident, arguing that prompt injection can turn hidden web content into unauthorized actions, data leakage, and account takeover when AI agents interpret injected instructions as trusted commands. Fingerprint recommends layered device intelligence, behavioral checks, and step-up authentication to challenge malicious browser automation before credentials or payment flows are completed. Details →First reported medium.com
Black Hat 2026: A Browser Bug Alone Is Harmless. Hand It to an AI Agent, and It Isn’t.
A Medium write-up covers research presented by Gareth Heyes at Black Hat USA 2026 showing that previously low-severity browser bugs — dismissed because they required improbable, precise user interaction — become dangerous account-takeover chains when an AI browsing agent, rather than a human, is the one interacting with the page. The proof-of-concept work covers multiple real chains, several already reported to and partially fixed by affected companies. Details →First reported infosecwriteups.com
Black Hat 2026: A Browser Bug Alone Is Harmless. Hand It to an AI Agent, and It Isn’t. | by Raj Namdev | Aug, 2026 | Medium
Coverage of research by Gareth Heyes presented at Black Hat USA 2026 demonstrating that previously low-severity browser bugs—often left unpatched because they required implausible user interaction—become account-takeover chains when an AI browsing agent, rather than a human, is the entity interacting with a page. The proof-of-concept work covers multiple real chains, several already reported to and partially fixed by the affected companies. Details →First reported darkreading.com
Agentic Browsers Rewind Web Security by 20 years
Zenity researchers, led by CTO Michael Bargury, disclosed a new class of vulnerabilities dubbed 'PleaseFix' affecting agentic browsers, to be presented at Black Hat. The flaws exploit how agentic browsers strip out cross-origin security mechanisms to let agents reach across web domains, enabling attacks ranging from account takeover to full browser escape and remote compromise of the underlying system. Details →First reported mallory.ai
Researchers Expose Prompt Injection and Cross-Origin Risks in AI Browsers
Researchers and vendors disclosed serious weaknesses in AI-enabled browsers, warning that agentic features undermine same-origin policy, tab isolation, and cross-origin content handling. In one chain against OpenAI's ChatGPT Atlas, Hacktron AI reported that exposed Chromium Mojo IPC interfaces reachable from allowlisted OpenAI origins were combined with a postMessage XSS on forums.openai.com and a login CSRF flaw to control browser functions, read live tab URLs, and steal OAuth codes enabling account takeover; OpenAI fixed it in Atlas 1.2025.288.15 and paid a $5,000 bounty. Brave separately detailed indirect prompt injection risks in Perplexity Comet. Details →First reported proofpoint.com
Account Compromise in the Agentic Workspace | Proofpoint US
Proofpoint threat research reviewing ATO activity across 50M+ accounts (November 2024–November 2025) found 99% of organizations were targeted by account takeover threats, 67% were successfully compromised, and 88% of impacted organizations experienced post-access abuse, with spear phishing succeeding twice as often as non-targeted attacks. The analysis argues that in agentic workspaces a compromised identity extends the blast radius into downstream AI agents, OAuth apps, and automated workflows tied to that identity, so login-only controls no longer suffice. Details →First reported neowin.net
People are using prompt injection to trick Meta's AI into handing over Instagram accounts
Attackers used prompt injection against Meta's AI support assistant on Instagram, sending crafted messages instructing it to link an attacker-controlled email to a target account, causing the AI to send password reset links to the attacker and bypassing 2FA. The exploit was reportedly active in the wild for months, compromising thousands of accounts including a dormant Obama White House account before being patched. Details →First reported twitter.com
Instagram account takeover exploit via support chatbot prompt injection (fixed)
Reports claim Meta's AI support agent for Instagram was granted account-modification permissions without identity verification, allowing attackers to manipulate the bot into changing account emails and bypassing 2FA, leading to live account takeovers. Multiple users reported losing accounts before the issue was reportedly patched. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector