Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
The work comes from Microsoft Incident Response and its
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Researchers at QiAnXin’s XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.
The end goal is a
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)
Fake Perplexity extension on Chrome Web Store tracked searches
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs.
“The campaign is delivered through unsigned installers – observed in both .NET and Golang variants – that
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use agents the firm tested. Only one, “Continue,” was built to
Lessons from the Underground: How to Combat Business Email Compromise
BlueHammer Vulnerability Exploited in Ransomware Attacks
The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.
The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek.
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key at all.
Whoever grabs it can send model requests on the developer’s account,
