First reported zitadel.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported proofpoint.com
Account Compromise in the Agentic Workspace | Proofpoint US
Proofpoint threat research reviewing ATO activity across 50M+ accounts (November 2024–November 2025) found 99% of organizations were targeted by account takeover threats, 67% were successfully compromised, and 88% of impacted organizations experienced post-access abuse, with spear phishing succeeding twice as often as non-targeted attacks. The analysis argues that in agentic workspaces a compromised identity extends the blast radius into downstream AI agents, OAuth apps, and automated workflows tied to that identity, so login-only controls no longer suffice. Details →First reported mitiga.io
MCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chain
Mitiga Labs research details a man-in-the-middle attack chain against Claude Code in which a user-level post-install hook rewrites MCP server endpoints in ~/.claude.json to route MCP traffic through attacker-controlled infrastructure and steal OAuth tokens for connected SaaS (Jira, Confluence, GitHub, etc.). Because provider-side audit logs still show valid OAuth traffic from Anthropic's trusted egress range, the malicious activity blends in as legitimate user actions, and token rotation fails to break the chain while the hook keeps reseeding the config. Details →First reported bleepingcomputer.com
The Replicant in Your Directory: AI Agents and the Identity Security Gap
A sponsored analysis piece by Netwrix CEO Grady Summers argues that AI agents, service accounts, OAuth apps, and other non-human identities now vastly outnumber human users and fall outside identity governance built for people. It cites the 2025 UNC6395 campaign, in which an OAuth token tied to Salesloft's Drift integration was abused to pivot across hundreds of Salesforce environments and reach AWS/Snowflake credentials, as an example of how a single trusted machine identity can cascade—an issue AI agents accelerate by creating and inheriting identities at machine speed. Details →First reported · updated · 2 reports talosintelligence.com
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos documents ARToken, a phishing-as-a-service affiliate panel sharing infrastructure with the EvilTokens platform, that abuses Microsoft's OAuth device authorization grant to steal tokens and bypass MFA. The AI element is an AI-augmented BEC pipeline chaining Groq-hosted Llama models for financial exposure scoring and GPT-4o-mini for email translation, plus AI-powered personalized lures, to automate fraud against compromised Microsoft 365 mailboxes. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector