First reported daily.dev
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported threatdown.com
Criminal AI tool Kriminal is mostly just Grok with a jailbreak, ThreatDown finds
ThreatDown analysis, reported by SiliconANGLE, found that the criminal AI tool marketed as 'Kriminal' is largely just xAI's Grok wrapped with a jailbreak that bypasses safety guardrails to produce illicit content. The tool is sold to cybercriminals as a purpose-built malicious LLM but relies on circumventing a commercial model's protections rather than being a bespoke system. Details →First reported threatdown.com
How Grok unknowingly powers cybercrime
ThreatDown (Malwarebytes) research analyzed 'Kriminal,' a clearnet-indexed, crypto-paid 'no filters, no guardrails' AI service marketed to cybercriminals for OSINT dossiers, exploit development, on-chain tracing, and social-engineering personas starting at $12.99/month. Analysis of Kriminal's own code found it is not an original model but a reseller wrapper around Grok, contradicting its claim to be a purpose-built criminal AI. Details →First reported economictimes.com
CrimeGPT comes knocking: Illegal AI services make cybercrimes cheaper and faster - The Economic Times
An Economic Times article, 'CrimeGPT comes knocking,' reports on the rise of illegal AI services (WormGPT/FraudGPT-style tools) that lower the cost and speed of committing cybercrimes. The provided text is largely site navigation with the substantive body behind the site's structure. Details →First reported github.com
GitHub - gaur-avvv/wormxgpt: No limits. No filters. No restrictions. WormXGPT is a unified AI tooling suite containing both a premium Hacker-themed React Web Dashboard and an advanced Unfiltered CLI agent. It features 150+ tools, multi-server MCP integration, auto-fallback across 30+ providers, and local workspace integration.
WormXGPT is a GitHub-published "unfiltered" AI tooling suite (repo gaur-avvv/wormxgpt) marketed with the tagline "No limits. No filters. No restrictions," combining a hacker-themed web dashboard and a CLI agent with 150+ tools, multi-server MCP integration, and auto-fallback across 30+ AI providers. The project is presented as an unrestricted, jailbroken AI agent framework echoing WormGPT-style malicious LLM tooling. Details →First reported femtosec.io
MessiahGPT: Inside the Uncensored Cybercrime AI
An analysis published on femtosec.io describes MessiahGPT, an uncensored Mixture-of-Experts LLM operated by the cybercrime group Dabial Leaks (formerly narxissist Forums) and sold on underground forums in tiered offerings (JinnatGPT, ParaohaGPT, MessiahGPT 2.0). The platform reportedly automates malware generation, exploit writing, social engineering pretexting, and parsing of leaked database dumps with no safety guardrails, and defenders are advised to block egress to messiahgpt.de and monitor DNS queries to known dark-AI domains. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector