First reported arxiv.org
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported paloaltonetworks.com
Analyzing the Current State of AI Use in Malware
Palo Alto Networks Unit 42 published a threat-research analysis examining how malware authors are currently incorporating generative AI and LLMs (such as ChatGPT) into their tooling, referencing observed samples including infostealers and Sliver-based implants. The piece assesses the practical maturity and limitations of AI use in real-world malware based on analyzed artifacts. Details →First reported bleepingcomputer.com
How enterprise GenAI can amplify ransomware risk — and how to contain it
A sponsored article by Acronis on BleepingComputer argues that enterprise generative-AI assistants and agents amplify ransomware risk by inheriting the identities, permissions, and data access that attackers already target. It outlines two threat models—attackers using AI to scale their own operations, and organizations exposing new attack surface through autonomous AI agents with delegated authority connected to SaaS, document repositories, and internal knowledge bases. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector