First reported · updated · 5 reports forcepoint.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported bunnyhoneyclub.com
North Korea's Fake Remote Workers Could Get You Sanctioned
A blog post covers a July 31, 2026 joint alert from eleven governments warning that North Korean IT workers are using real-time AI deepfakes and large language models to pass live video interviews and get hired into remote developer roles, funneling salaries to fund the regime's weapons programs. It cites OFAC sanctions of six individuals and two entities in March 2026 and a 2025 Justice Department sweep of 29 'laptop farms' affecting more than 100 US companies. Details →First reported chubbworks.com
Underground AI Supercharges Phishing Attacks On ...
Cybersecurity researchers report underground jailbroken generative-AI models such as WormGPT and FraudGPT being marketed on dark-web and hacker forums to help criminals draft convincing phishing emails, write or modify malware, identify vulnerabilities, and automate parts of attacks. The piece frames this as a growing trend that lowers the skill barrier for business email compromise and other fraud, and offers defensive recommendations for employers. Details →First reported sciencedirect.com
From AI-generated content to agentic action: Security and safety threats in generative AI
A review paper in the Journal of Information and Intelligence titled 'From AI-generated content to agentic action' surveys the security and safety implications as generative AI systems move from producing content to retrieving data, invoking tools, and executing actions through tool chains and external APIs. It analyzes content-level, model-level, and agentic threats alongside countermeasures such as detection, watermarking, alignment, and emerging agentic safeguards, arguing that attack-surface expansion outpaces defensive responses. Details →First reported darkreading.com
New Tool Traces AI Videos Back to Their Source
UC Riverside researchers built SAGA (Source Attribution of Generative AI videos), a framework that not only detects whether a video is AI-generated but also identifies the specific generative model, its version, and the development team for forensic attribution. The tool aims to counter deepfake-driven disinformation, impersonation, and social-engineering threats such as fraudulent deepfake job applicants. Details →First reported ssrn.com
Jailbreak-as-a-Service: The Emerging Threat Landscape by Chetan Pathade, Vinod Dhiman, Sheheryar Ahmad :: SSRN
A research paper by Chetan Pathade, Vinod Dhiman, and Sheheryar Ahmad examines the emergence of Jailbreak-as-a-Service (JaaS) as a structured underground economy that commoditizes prompt-based attacks against LLMs. It provides a taxonomy of the JaaS ecosystem — marketplace platforms, pricing models, and distribution channels from Telegram bots to subscription web portals — reporting attack success rates of 65-78% against major LLM providers and evaluating the inadequacy of current guardrail defenses. Details →First reported arxiv.org
Decoding the Threat Landscape : ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks
An arXiv paper by Polra Victor Falade, 'Decoding the Threat Landscape: ChatGPT, FraudGPT, and WormGPT in Social Engineering Attacks,' uses a blog-mining technique to survey how generative AI models empower attackers to craft personalized phishing lures, produce deepfakes, and exploit cognitive biases. The paper also outlines defensive strategies including traditional and AI-powered security measures. Details →First reported · updated · 4 reports arxiv.org
Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies
A survey paper by Kiarash Ahi and Saeed Valizadeh reviews over 70 academic papers, industry reports, and technical documents on the dual-use of LLMs and generative AI in cybersecurity, covering AI-generated malware, zero-day detection, explainable AI, and defensive strategies. Drawing on case studies from platforms like Google Play Protect, Microsoft Defender, and Hugging Face, it offers recommendations including model watermarking, adversarial defense, and cross-industry collaboration. Details →First reported arxiv.org
Dynamic Defense Profiling Enables Cognitive Jailbreak of Text-to-Image Models
Researchers present MIND, a cognitive jailbreak framework that models a text-to-image system's latent defense mechanisms as a belief-state inference problem, interpreting multi-modal feedback (textual refusal, visual blocking, semantic sanitization) to iteratively craft adversarial prompts that produce NSFW content. Using a Multi-modal Judge, Defense Profiler, and Meta-Memory module, MIND reports a 95.62% attack success rate against defended Stable Diffusion v1.5 and up to 91.58% against commercial T2I systems like Wan-2.5. Details →First reported dailyjus.com
Prompt Injection: Are Invisible Instructions the Next AI Risk in Disputes? – Daily Jus by Jus Mundi
Legal analysts at Greenberg Traurig examine prompt injection as an emerging AI risk in legal disputes, describing how hidden instructions embedded in documents can manipulate AI tools that ingest them into producing skewed or incomplete outputs. The piece contrasts this with AI hallucinations and notes a court has already dealt with the issue. Details →First reported amazon.com
Designing for the inevitable: System prompt leakage and mitigations in generative AI applications | AWS Security Blog
An AWS Security Blog post titled "Designing for the inevitable: System prompt leakage and mitigations in generative AI applications" discusses the risk of system prompt leakage in LLM-based applications and offers guidance on mitigations, referencing the OWASP Top 10 for LLM Applications (LLM07: System Prompt Leakage). Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector