Ai-Infrastructure
Verification Theater: The One-Week Pattern Behind BragJack, Plugin4Shell, and WSO2's JWT Bypass
Three unrelated disclosures landed between September 13 and 19, 2026 β a browser AI agent hijack, a Git SHA-pinning bypass in every major coding agent, and a JWT auth bypass under active exploitation. All three share one root cause: a check that confirms a label matches instead of verifying the object it names.
BragJack: One Malicious Extension Hijacks AI Agents Across Five Major Browsers
Researcher Gal Weizman's BragJack proof-of-concept shows how a single malicious extension can hijack the built-in AI agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, earning $20K+ in bounties and two CVEs (CVE-2026-0628, CVE-2026-55945).
Plugin4Shell: SHA-Pinning Bypass Enables Zero-Click RCE Across Claude Code, Codex, Copilot, and Gemini CLI
A Git reference-resolution flaw dubbed Plugin4Shell lets a plugin repository owner silently swap the code behind a SHA-pinned install across all four major AI coding agents, achieving zero-click RCE on developer and CI machines that trust the pin.
CVE-2026-59971: MySQL MCP Server's SSE Mode Ships With No Auth, No Host Checks β CVSS 10
CVE-2026-59971 (CVSS 10) in the designcomputer mysql_mcp_server package leaves SSE/HTTP deployments wide open to unauthenticated SQL execution, reachable directly or via DNS rebinding, with no fix required beyond upgrading to 0.4.2.
CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation
CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation β VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.
The ECC Excuse Is Dead: A Hardening Guide for Multi-Tenant GPU Infrastructure After GPUThor
For four months, 'enable ECC' was the official fix for GPU Rowhammer. GPUThor just showed that advice was wrong. Here's what to actually change on GPU fleets that run untrusted CUDA code from more than one tenant.
NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding
CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.
Inside the AI-Orchestrated EDR Evasion Lab: What Sophos Actually Found, and Why the Bug Wasn't in the Malware
Sophos recovered a fully autonomous malware R&D pipeline β a coordinator agent, four subordinate agents, a self-provisioned lab, and 80 evasion modules built against three EDR vendors. The interesting part isn't that it worked. It's the one thing in the whole pipeline that didn't.
Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE
CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.
Copilot for Word Can Be Turned Into a Self-Propagating AI Worm β No Comprehensive Fix After 144 Days
Researcher HΓ₯kon MΓ₯lΓΈy's 'Context Collapse, Part 3' shows hidden document instructions can make Copilot for Word rewrite content and copy the payload into every new file it touches β and Microsoft's fixes, including a model upgrade to GPT-5.5, haven't closed the underlying attack class.
Negative Time-to-Exploit: AI Bug Hunting Just Broke the One Assumption Your Patch Cycle Depends On
Kimi K3 found 19 Redis zero-days in 90 minutes. XBOW is #1 on HackerOne's global leaderboard. Anthropic's Mythos Preview found thousands of unpatched flaws across every major OS and browser. Meanwhile the average critical vulnerability still takes 252 days to fix. That gap is now the whole game.
AI Agents Find Two New Redis RCE Chains in Under 90 Minutes
Kimi K3 agents surfaced a stream shared-NACK double-free and a RedisBloom TDigest heap overflow across Redis 6.2 through 8.8, both yielding authenticated remote code execution. Patches are out; no in-the-wild exploitation reported yet.
Hidden Web Text Turns AWS Kiro Into an RCE Chain: MCP Config Rewrite via Prompt Injection
Researchers at Intezer and Kodem Security show how hidden text on an ordinary web page could make AWS's Kiro agentic IDE rewrite its own MCP config and execute attacker code β no approval dialog, no CVE, patched in Kiro 0.11.130.
Hugging Face Discloses Breach Driven End-to-End by an Autonomous AI Agent
An unauthorized party used an autonomous AI agent swarm to chain two dataset-processing code-execution flaws into a multi-cluster breach at Hugging Face, harvesting cloud credentials before the company detected and evicted it over a weekend.
The Agent Is the Payload: How AI Coding Agents Became 2026's Fastest RCE Pipeline
Six incidents in six weeks show the same failure mode: AI coding agents treat untrusted text as instructions and shell access as a convenience feature. Prompt injection to RCE is no longer theoretical β it's a documented, repeatable kill chain, and the guardrails vendors are shipping don't touch the actual boundary.
PraisonAI: Two More Critical RCEs (CVE-2026-61445, CVE-2026-61447) as AICoder Runs LLM Output Unsandboxed
PraisonAI's AICoder component writes files and executes shell commands straight from LLM tool calls with no path validation, and CodeAgent._execute_python() runs LLM-generated Python with no AST checks or sandboxing β two CVSS 9.9 and 10.0 flaws, patched in 4.6.78.
Langflow Hit With Its Second CISA KEV Entry in Four Months: CVE-2026-55255 IDOR Under Active Exploitation
CISA adds Langflow CVE-2026-55255, an IDOR letting authenticated attackers hijack other users' AI workflows, to its KEV catalog after Sysdig caught in-the-wild exploitation chained with secret harvesting.
JADEPUFFER: First Documented Ransomware Attack Run End-to-End by an AI Agent
Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited a year-old Langflow RCE (CVE-2025-3248) to breach, pivot, and encrypt a production database with zero human operator input.
DuneSlide: Zero-Click Prompt Injection Chains to Full RCE in Cursor IDE (CVE-2026-50548, CVE-2026-50549)
Two critical Cursor IDE flaws, dubbed DuneSlide, let a poisoned MCP response or web search result steer the agent's own sandbox into overwriting its enforcement binary β zero-click prompt injection to unsandboxed remote code execution, patched in Cursor 3.0.
GuardFall: Decades-Old Bash Quoting Tricks Defeat Safety Guards in 10 of 11 Open-Source AI Coding Agents
Adversa AI's GuardFall research shows that quote removal, $IFS spacing, command substitution, and other decades-old shell tricks bypass the command guards in opencode, Goose, Cline, Aider, and seven other open-source AI coding agents β turning a poisoned README into silent credential theft.