First reported darkreading.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported heyitsas.im
OVSwrap: another Linux local root vulnerability
OVSwrap (CVE-2026-64531, CVSS 7.8) is a Linux kernel Open vSwitch datapath memory-corruption bug that lets an unprivileged local user gain root on broadly default-configured distributions, with a public exploit shipping pre-built offsets for ~800 kernel builds. Researcher Asim Manizada disclosed it and, notably, says it was found by equipping LLM 'hunter agents' with graph-reasoning and persistent ASCII-diagram memory-geometry tools to reason through the 16-bit Netlink length wraparound that redirects parsing into attacker-controlled conntrack data. Details →First reported umvwebsecurity.com
AI Vulnerability Discovery Is Reshaping the Front of the Cyber Kill Chain
An analysis piece argues that AI-assisted vulnerability discovery is compressing reconnaissance, source-code review, and exploit validation at the front of the cyber kill chain, lowering the cost of initial access. It cites Google's Big Sleep agent surfacing CVE-2025-6965 in SQLite, DARPA's AI Cyber Challenge, and researcher Sean Heelan using OpenAI's o3 to find CVE-2025-37899 in the Linux kernel SMB implementation, and recommends integrating AI-assisted auditing into vulnerability management workflows. Details →First reported theregister.com
AI-found bugs aren't proving any easier to exploit despite the hype
VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, cross-referencing them against its Known Exploited Vulnerability database, and found only 14 (1.3 percent) confirmed exploited in the wild — nearly identical to the baseline rate for all vulnerabilities. The research concludes AI mainly increases the volume of flaws researchers uncover rather than the share attackers weaponize, suggesting claims that frontier AI dramatically favors attackers are overhyped. Details →First reported darkreading.com
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Dark Reading reports that two new Chinese AI models—Zhipu AI's open-weight GLM 5.2 and 360 Security Technology's Tulongfeng ('Dragon Saber')—are performing strongly on vulnerability-discovery benchmarks, with GLM 5.2 said to outperform Anthropic Opus and GPT-5.5 on some bug-finding tests at low cost, and 360 claiming its tool has already found more than 3,400 vulnerabilities. Experts warn that commodity models now widen the gap between attackers and defenders. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector