First reported · updated · 9 reports openai.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported trendmicro.com
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America | Trend Micro (US)
Unit 42 and Trend Micro report two distinct threat campaigns (tracked as SHADOW-AETHER-040/CL-CRI-1131 and SHADOW-AETHER-064/CL-CRI-1163) that used agentic AI command-line tools to drive intrusion operations against government, financial, aviation, and retail organizations across Latin America. Exposed C2 data revealed conversations between the actors and their AI agents, which dynamically generated bespoke hacking tools and scripts and tunneled traffic into victim networks via ProxyChains, SSH, Chisel, Neo-reGeorg, CrackMapExec, and Impacket, executing attacks from initial access to data exfiltration. Details →First reported nvidia.com
Building an Adaptive Agentic Cybersecurity System with NVIDIA Nemotron
NVIDIA and CrowdStrike describe an evaluation of an adaptive agentic cybersecurity system that links offensive and defensive AI agents into a closed loop at machine speed, built on Nemotron open models and Falcon telemetry within an isolated environment. Backtesting showed a 41.9% mean detection rate (a 2.5x improvement over the default harness), and live-fire testing against eight unseen attacks found 45% of open-model detections generalized versus 29% for the frontier system. Details →First reported arizona.edu
LLM-Based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery - University of Arizona
A peer-reviewed IEEE Access survey and tutorial from University of Arizona researchers reviews LLM-based autonomous agents for automated vulnerability discovery and penetration testing, synthesizing 155 sources (2022–early 2026) and walking through four phases: mission scoping/prompt engineering, autonomous exploration and tool selection, vulnerability hypothesis formation, and payload generation. It covers multi-agent architectures, reasoning-class models, the Model Context Protocol ecosystem, autonomous bug-bounty agents, and agentic security benchmarks. Details →First reported github.com
GitHub - xalgord/xalgorix: Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Xalgorix is an open-source project on GitHub (xalgord/xalgorix) presenting autonomous AI pentesting agents that perform real-time reconnaissance, vulnerability detection, and exploitation orchestration, built in Go and TypeScript with active releases (v4.5.69) and commit history. Details →First reported getastra.com
Autonomous AI Agents for Penetration Testing: A Complete Guide
A guide from Astra Security explains how autonomous AI agents are being used for penetration testing, describing agentic systems that reason, chain exploits, and validate impact end-to-end, and surveying vendors such as Astra, XBOW, Horizon3.ai, Pentera, and Aikido. It references academic systems including PentestGPT and the ARTEMIS multi-agent framework, which in a live ~8,000-host university network study placed second overall, out-performing 9 of 10 human testers while showing higher false-positive rates. Details →First reported thehackernews.com
Dawn of the Apex Agentic Adversary
An analysis piece arguing that autonomous, agentic AI adversaries are compressing the timeline of cyberattacks beyond human-speed defenses, ending the era of human-paced threat cycles. The available text is introductory commentary without specific technical proof-of-concept details. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector