First reported digicert.com
Lead dispatch
First reported island.io
AgentBaiting: How Fake AI Skills Deliver Malware at Scale
Island security researchers uncovered the FakeGit campaign, which used roughly 7,600 malicious GitHub repositories—over 800 posing as AI Skills or MCP servers—to deliver SmartLoader malware that installs the StealC information stealer. The campaign introduces a technique called AgentBaiting, in which AI agents such as Claude Code, Gemini, and ChatGPT autonomously discover the attacker repositories, treat the malicious README as legitimate documentation, and pass installation instructions to users; the operation recorded over 14 million downloads.supply-chain · tool-abuse · malware-delivery · agentbaiting
mcp · ai-agents · ai-skills · llm · copilot
Severity
0.75
The wire · latest
First reported darkreading.com
AI-Generated Workflows Are a Silent Security Disaster
An opinion/commentary piece arguing that AI coding assistants used to generate Microsoft 365 automation (e.g., Power Automate workflows) create unreviewed permissions and data flows, citing an incident where an AI-generated workflow copied sensitive HR documents into a broadly accessible Teams channel. The piece frames this as a governance and oversight gap rather than presenting a specific reproducible exploit. Details →First reported skilldb.dev
Shipping an OAuth-protected remote MCP server: the spec, 3 security bugs, and a Cloud Run gotcha
An engineering blog post from SkillDB describing how they turned their MCP server into a remote, OAuth-protected MCP server for Claude Desktop, covering the MCP authorization spec (RFC 9728 protected resource metadata, 401 Bearer challenge), three OAuth security bugs caught in review before launch, and a Cloud Run infrastructure issue. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector