First reported · updated · 4 reports thehackernews.com
Lead dispatch
First reported · updated · 3 reports embracethered.com
AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection
Researchers found a vulnerability (CVE-2026-10591) in AWS Kiro, an agentic IDE, where hidden instructions planted in a web page or source file that Kiro processes can trigger indirect prompt injection to rewrite Kiro's own MCP server configuration (~/.kiro/settings/mcp.json) or allowlist arbitrary Bash commands in .vscode/settings.json, achieving arbitrary code execution on the developer's machine with no approval prompt. The human-in-the-loop approval boundary is bypassed because Kiro can write to these config files without user consent, and AWS has issued a fix and CVE.indirect-prompt-injection · prompt-injection · remote-code-execution · tool-abuse · config-poisoning
ai-agents · mcp · llm · agentic-ide
The wire · latest
First reported encryptionconsulting.com
Shadow AI Agents: How to Discover and Govern Unmanaged Autonomous Agents
Encryption Consulting explains "shadow AI agents" — autonomous agents running in an enterprise without a named owner, scoped identity, or inventory entry — outlining four common origination paths (internal scripts/automation, SaaS copilot features enabled by default, low-code/RPA workflows, and MCP integrations) and proposing a discovery, risk-scoring, ownership, and credential-governance program to manage them. Details →First reported · updated · 5 reports forcepoint.com
What Is Shadow AI? How to Detect and Prevent It
"What Is Shadow AI? How to Detect and Prevent It" is an explainer on unsanctioned employee use of generative-AI tools (shadow AI), the data-leakage and compliance risks it creates, and defensive practices for discovering and governing such tools. The piece references supporting material including OpenAI's enterprise-privacy commitments and a Wiz-disclosed exposure of a misconfigured Moltbook database that leaked 1.5 million API tokens. Details →First reported substack.com
Going Deeper: The MCP Inventory Gap - by Rod Trent
Rod Trent's post examines the 'MCP inventory gap' in Microsoft environments, where different consoles report wildly different counts of MCP servers/connections — 122 Copilot connectors in the M365 admin center versus 5 MCP servers shown in the Security Dashboard for AI and Defender Applications. The piece argues each console answers a different governance question rather than being reconcilable views of one list, and offers guidance on how defenders should interpret and assess MCP visibility for Copilot governance. Details →First reported blackduck.com
The AI coding security gap: Why faster development demands stronger guardrails
A Black Duck blog by Steve Smith argues that AI coding assistants accelerate development while multiplying application-security risk, citing a Stanford study finding that developers with AI assistants wrote less secure code and were overconfident about it. The piece outlines root causes of insecure AI-generated code, new attack vectors (including shadow AI and supply-chain risks like slopsquatting), and a seven-layer defensive strategy. Details →First reported akamai.com
Top 5 Enterprise AI Risks 2026 Research
Akamai's State of the Internet: Enterprise AI Usage Risk Report 2026 (drawing on LayerX telemetry) finds that the top 5% of enterprise AI power users interact with AI models at 12 times the rate of the bottom 50%, hardcoding unvetted AI tools into critical operations. The report enumerates the top five enterprise AI risks, including shadow AI from personal accounts, data leakage, unnoticed browser/IDE extensions, and AI agents operating outside guardrails, citing named attack techniques such as CursorJacking and CometJacking. Details →First reported pushsecurity.com
How to discover AI, enforce policies, and prevent data loss
A Push Security blog argues that blocking AI tools at the network level drives shadow AI underground, and outlines a governance approach for discovering unapproved AI apps, browser extensions, OAuth integrations, and MCP connections, plus enforcing data-flow controls (blocking uploads/downloads/clipboard pastes and monitoring AI chat transcripts). The piece cites telemetry claiming the average organization runs 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in a typical week, most unapproved. Details →First reported · updated · 3 reports redmondmag.com
Agent Sprawl Is the New Shadow IT And You Probably Can't Count Yours
Redmond Magazine reports on how Microsoft is using its Agent 365 control plane to govern and inventory hundreds of thousands of AI agents across its internal environment, addressing what it calls agent sprawl. The approach centers on automatic metadata collection, ownership, lifecycle tracking and risk signals for agents created via Microsoft 365 Copilot, SharePoint, Teams, Copilot Studio, Microsoft Foundry and third-party platforms. Details →First reported bcs.org
How AI is reshaping threats and the steps needed to reduce risk
An opinion piece by Katerina Tasiopoulou (CEO of Threatscene) published by BCS argues that AI is reshaping the cyber threat landscape by expanding the attack surface to include foundation models, training/inference data, prompts, AI APIs, vector databases and automated workflows. The article discusses shadow AI, third-party AI supply-chain dependency and the economic asymmetry between cheap attacker tooling and costly defensive investment, recommending centrally governed, monitored AI security. Details →First reported · updated · 6 reports aquilax.ai
Shadow MCP: Find and Lock Down Rogue MCP Servers | PipeLab
"Shadow MCP" describes the emerging risk of employees deploying unvetted Model Context Protocol servers without IT oversight, granting AI agents direct access to production databases, file systems, and internal APIs. The article, from AquilaX/PipeLab, frames this as 2026's shadow-IT problem and discusses discovering and locking down rogue MCP servers. Details →First reported aona.ai
AI Agents Are Finding Zero-Days Faster Than Security Teams Can Govern Them
An Aona AI blog post analyzes how autonomous AI security agents are discovering zero-days at unprecedented speed, citing a startup that reported 21 previously unknown FFmpeg vulnerabilities with reproducible PoCs for about $1,000 of compute, and Google patching a record 429 Chrome bugs after adapting its bounty program to a flood of AI-generated reports. The piece argues the bottleneck has shifted from discovery to validation, governance, and trust in AI-generated findings. Details →First reported jetico.com
Shadow AI Agents: Why Access Control Is the Missing Layer
Jetico's blog post argues that AI agents installed on employee endpoints inherit the user's permissions, turning "shadow AI" from a copy-paste data-leak problem into an autonomous access problem where an unapproved agent can read every file the user's account can open. The post cites Traficom (Finnish Transport and Communications Agency) guidance on agent permissions and advocates default-deny, file-level access control as a mitigation. Details →First reported digicert.com
AI Deployment Outpaces AI Accountability
A commissioned DigiCert survey of 1,001 IT and security leaders reports that 78% of enterprises experienced AI-related security incidents or identified AI-related vulnerabilities, with incidents attributed largely to unauthorized or misconfigured AI agents rather than AI-generated code. The report frames the problem as a lack of AI governance and identity controls for non-human/agent actors, echoing a similar Spacelift finding. Details →First reported thehackernews.com
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
The article argues that shadow AI in enterprises has evolved from a data leakage concern into an access control problem, where the risk lies in autonomous AI tools and agents having unmanaged access permissions rather than just employees pasting sensitive data. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector