Related Threat Clusters
-
Tracebit's Context Bombs Turn AI Attackers' Guardrails Against Them
Security firm Tracebit has introduced a novel defense mechanism called 'context bombs' that can thwart AI-powered cyberattacks. By embedding specific strings of text within cloud decoy resources, these context bombs…
2 articles · Updated July 15, 2026 -
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
OrcaRouter AI Threat Report 2026 Highlights Rising Prompt Injection Risks
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
3 articles · Updated June 22, 2026 -
Hackers Exploit Marimo RCE Using LLM Agent for Rapid Database Access
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
5 articles · Updated May 28, 2026 -
AWS Bedrock Sandbox Vulnerability Enables DNS-Based Data Exfiltration
A security flaw in AWS Bedrock's AgentCore Code Interpreter allows attackers to bypass network isolation through DNS queries. Researchers from BeyondTrust demonstrated that the sandbox mode permits outbound DNS queries…
7 articles · Updated March 17, 2026 -
Risks of Privilege Abuse in Multi-Agent AI Systems Highlighted
Multi-agent AI systems are vulnerable to privilege abuse when agents delegate tasks across complex chains. This risk, classified by OWASP as Identity & Privilege Abuse, can lead to agents exceeding their original…
2 articles · Updated July 6, 2026 -
AI-Powered Vulnerability Sweep Reveals 15,000 Flaws in MCP Servers
A recent Trendmicro report identified over 15,000 vulnerabilities across 19,000 open-source MCP servers, with a significant portion potentially influenced by AI-generated code. The research utilized a Gemini-powered AI…
2 articles · Updated May 28, 2026 -
LexisNexis Data Breach by FulcrumSec Exposes Customer Information
On March 3, 2026, the threat actor FulcrumSec claimed responsibility for a data breach at LexisNexis Legal & Professional, resulting in the exfiltration of 2.04 GB of structured data from the company's AWS cloud…
16 articles · Updated March 3, 2026 -
Shai-Hulud Malware Infects npm Packages, Compromising Thousands of Repositories
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…
43 articles · Updated November 29, 2025 -
AWS Launches AI Security Framework to Enhance Security for AI Workloads
On May 15, 2026, AWS introduced the AI Security Framework aimed at helping organizations secure AI workloads. The framework provides a structured model that aligns security controls with specific AI use cases, layers,…
2 articles · Updated May 15, 2026
Recent Intelligence Reports
- Prompt Injection Flipped: Defender Plants Text That Stops AI Attackers — Techtimes · July 15, 2026
- Tracebit's 'context bombs' flip LLM guardrails to trap AI attackers — Aiweekly.Co · July 14, 2026
- Jscrambler Npm Supply Chain Compromise — safedep.io · July 13, 2026
- Enforce least-privilege authorization in multi — Aws.Amazon · July 6, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid ... — Bignewsnetwork · June 23, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid ... — Irishsun · June 22, 2026
- OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid Rise in Prompt-Injection Attacks — Aninews.In · June 22, 2026
- Attackers Use LLM Agent After Marimo Exploit | Let's Data Science — Letsdatascience · May 29, 2026