Between March and May 2026, Zenity researchers observed three distinct campaigns where attackers hijacked exposed AI endpoints from Ollama and LiteLLM for offensive operations. The attackers exploited inference…
Andrew Ng launched Context Hub, a service for coding agents to access API documentation, which has been found to have significant security vulnerabilities. Mickey Shmueli demonstrated a proof-of-concept attack showing…
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit…
State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…
Vulnerabilities in Anthropic's MCP server allow for code execution and data exposure through prompt injections. Researchers from a security firm demonstrated how these flaws could be exploited, impacting the official…
Security researchers have identified a vulnerability in Cursor, an AI-powered code editor, that allows rogue Model Context Protocol (MCP) servers to inject malicious code into its internal browser. This exploit can…
Hackers are exploiting a critical vulnerability in Cursor, an AI-powered code editor, by using compromised Model Context Protocol (MCP) servers to inject malicious code. This attack allows the rogue servers to…