First reported simonwillison.net
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported thehackernews.com
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
An opinion piece from The Hacker News argues that generative AI and LLMs are collapsing the traditional attacker-sophistication ranking by letting low-skill 'script kiddie' adversaries close knowledge gaps — accelerating research, generating code, troubleshooting, and adapting known techniques. The article frames 'vibe hacking' as lowering the barrier to entry and changing the economics of offensive security. Details →First reported google.com
Adversarial Misuse of Generative AI | Google Cloud Blog
Google Threat Intelligence Group (GTIG) published an analysis of how government-backed threat actors, information operations groups, and cyber criminals interacted with its Gemini AI assistant, finding that adversaries currently use it mostly for productivity gains (research, coding assistance, reconnaissance) rather than novel AI-enabled attacks. The report contrasts theoretical AI-misuse research against real-world observed usage across multiple nation-state and criminal actors. Details →First reported snyk.io
The Attacker Never Sleeps, Neither Can Your Testing
Snyk's Manoj Nair argues in an opinion piece that frontier reasoning-grade AI models have removed the human time and cost constraints on attackers, letting adversaries reason about applications at machine speed and weaponize entire vulnerability backlogs. The post cites Five Eyes warnings and Anthropic's disclosure of a state-sponsored group that used its models to run most of a live espionage campaign, framing the risk as a growing 'trust gap' between AI-generated code and testing capacity. Details →First reported darkreading.com
'Yellow Teams' Are Defining the Future of AI Security
A Dark Reading feature describes the emergence of 'yellow teams' — engineers who build both AI-driven attack frameworks and defenses — spurred by security-focused frontier models such as Anthropic's Claude Mythos (Project Glasswing) and OpenAI's GPT 5.5 (Daybreak). Cloudflare's accompanying report on Mythos Preview details the model autonomously constructing exploit chains and generating working proofs by compiling and running trigger code against more than fifty of its own repositories. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector