First reported · updated · 2 reports sygnia.co
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported · updated · 4 reports deepinspect.ai
MCP Server Security: How Malicious Tools Attack AI Agents | Precursor Security
An analysis of Model Context Protocol (MCP) server security synthesizes research showing publicly exposed, unauthenticated MCP servers nearly tripled from 492 (July 2025) to 1,467 (April 2026) per Trend Micro, that 33% of scanned servers carry critical vulnerabilities (Enkrypt AI), that static long-lived secrets dominate authentication (Astrix), and that 24,008 secrets leaked in MCP config files (GitGuardian). It frames these exposures against attack classes such as tool poisoning, credential theft via prompt injection, lateral movement, and full cloud compromise, referencing the OWASP MCP Top 10. Details →First reported darkreading.com
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov released NHI Hound, an open source tool to discover dormant non-human identities and map trust paths in cloud environments, after investigating an incident where an idle AI-enabled workflow agent suddenly began firing API calls and was found to have moved laterally and escalated privileges via 'ghost credentials.' The tool helps surface tokens, agents, and service accounts that live outside traditional trust boundaries in heavily automated, AI-based environments. Details →First reported proofpoint.com
Account Compromise in the Agentic Workspace | Proofpoint US
Proofpoint threat research reviewing ATO activity across 50M+ accounts (November 2024–November 2025) found 99% of organizations were targeted by account takeover threats, 67% were successfully compromised, and 88% of impacted organizations experienced post-access abuse, with spear phishing succeeding twice as often as non-targeted attacks. The analysis argues that in agentic workspaces a compromised identity extends the blast radius into downstream AI agents, OAuth apps, and automated workflows tied to that identity, so login-only controls no longer suffice. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector