First reported cloudsek.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported sciencedirect.com
A systematic literature review of large language models in phishing attack generation and detection
A systematic literature review (PRISMA methodology, 36 studies from 2023-2025) examines the dual role of large language models in both generating and detecting phishing attacks. The review finds LLMs, especially GPT-based models, lower the technical barrier for attackers by producing coherent, persuasive phishing email and website content, while also strengthening detection through analysis of textual and visual content, often outperforming traditional machine-learning approaches. Details →First reported thehackernews.com
Growing Up The Hard Way
An editorial essay from The Hacker News, "Growing Up The Hard Way," uses a coming-of-age metaphor to describe how open source software now faces AI-driven security pressure, citing real supply-chain incidents (SolarWinds, Log4Shell, Shai-Hulud) and framing a two-front threat: "Mythos-class AI" discovering chained zero-days faster than defenders can triage them, alongside industrialized poisoning of software distribution channels. Details →First reported · updated · 3 reports trussed.ai
Top Agentic AI Security Threats in Late 2026
An introductory blog on the AI Innovation Stack argues that authenticated AI agents are not necessarily aligned, framing the shift as the collapse of decades of enterprise security assumptions built for human or deterministic actors. It cites a real AI-assisted campaign in which a single operator, using two commercial AI tools that generated roughly three-quarters of the remote command execution, breached nine Mexican government agencies and exfiltrated about 195 million identity records over 2.5 months. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector