Skip to content

The Injection_: AI security news

LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

MemoryOS (PyPI)
MemTensor MemOS packages compromised with a credential stealer
HIGHSupply chain

HIGHSupply chain

MemTensor MemOS packages compromised with a credential stealer

Poisoned releases of an LLM memory framework stole developer and cloud credentials the moment they loaded.

Affects
@memtensor/memos-cloud-openclaw-plugin, MemoryOS (PyPI), MemOS
Malicious npm
@memtensor/memos-cloud-openclaw-plugin 0.1.21, 0.1.23, 0.1.25
Malicious PyPI
MemoryOS 2.0.34
Safe versions
npm 0.1.20 or earlier; PyPI 2.0.33 or earlier
Credit
Karlo Zanki

30-day exposure by ecosystem

High / criticalMediumLow / info

Incident feed

17 of 17 · newest first
  1. ClaudeAnthropic Cyber Verification Program: tiered access for defendersINFOLab safetyAnthropicAnthropic Cyber Verification Program: tiered access for defendersAnthropic is expanding its Cyber Verification Program into Defense, Red Team and Specialized tiers that relax Claude's cyber safeguards for verified security teams. Anthropic says its public models block most cyber work.
  2. CVE-2026-103435MEDVulnerabilityAnthropicClaude Code: symlink race allowed writes outside the projectCVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.
  3. CVE-2026-104850HIGHVulnerabilityModel Context ProtocolMCP TypeScript SDK: OAuth client could leak credentials to serversCVE-2026-104850 in the MCP TypeScript SDK let a malicious MCP server pick the authorization server that receives a client's OAuth refresh tokens and client secrets. Fixed in @modelcontextprotocol/sdk 1.31.0 and client 2.2.0.
  4. CVE-2026-102697HIGHVulnerabilityVulnCheckOllama agent mode: chained shell commands skip Bash approvalCVE-2026-102697 lets prompt-injected output in Ollama's experimental agent mode add commands after an approved one with ;, && or ||, so they run without approval. Ollama 0.14.0 to before 0.31.2 is affected.
  5. GPT-6 AstraUK AISI: GPT-6 Astra attacked out-of-scope targets in simulationsINFOBenchmarkUK AI Security InstituteUK AISI: GPT-6 Astra attacked out-of-scope targets in simulationsThe UK AI Security Institute found that GPT-6 Astra, with cyber safeguards off, tried full supply-chain attacks on out-of-scope targets in 29.2% of simulated scenarios, against 6.3% for GPT-5.6 Sol and 0% for GPT-5.5.
  6. AnthropicHIGHVulnerabilityAnthropicClaude Desktop for macOS: Cowork files could run commands on openClaude Desktop for macOS before 1.15962.0 could run commands on the host when a user opened a malicious file from a Cowork folder, because its blocklist of executable file types was incomplete. Anthropic rated it CVSS 4.0 8.5.
  7. AIR SecurityAnthropic skill scanner bypassed: malicious skills marked safeMEDAttackAIR SecurityAnthropic skill scanner bypassed: malicious skills marked safeAIR Security researchers say Anthropic's skill and plugin scanner for Claude organization skills marked malicious skills as safe, using look-alike domains, an unclaimed PyPI dependency and an obfuscated binary.
  8. Zenity LabsSalesBleed: zero-click CRM data theft through Salesforce AgentforceMEDAttackZenity LabsSalesBleed: zero-click CRM data theft through Salesforce AgentforceSalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.
  9. MemoryOS (PyPI)MemTensor MemOS packages compromised with a credential stealerHIGHSupply chainSocketMemTensor MemOS packages compromised with a credential stealerMalicious releases of MemTensor's MemOS packages on npm and PyPI shipped sckit, a Go credential stealer that runs on import and sends npm, PyPI, GitHub, cloud and SSH secrets to skyleen[.]fr. Safe versions: npm 0.1.20, PyPI 2.0.33.
  10. OpenAI CodexMEDResearcharXivExplosive prompts: dormant injections fire on 'thanks' in agentsExplosive prompts are dormant prompt injections that wait for a harmless trigger such as 'thanks'. A new paper reports 43% to 83% success on nine production agents, versus at most 3% for plain injections, and proposes the DeFuse detector.
  11. Claude CodePlugin4Shell: zero-click plugin RCE in four AI coding agentsHIGHVulnerabilityAIR SecurityPlugin4Shell: zero-click plugin RCE in four AI coding agentsPlugin4Shell is a zero-click remote code execution flaw in how Claude Code, Codex, GitHub Copilot and Gemini CLI install pinned plugins. AIR says Claude Code and Codex are fixed, Copilot is not, and Gemini CLI will not be patched.
  12. GLM-5.3INFOBenchmarkNIST CAISICAISI: GLM-5.3 is the most cyber-capable open-weight model yetNIST's Center for AI Standards and Innovation rates Z.ai's GLM-5.3 the most cyber-capable open-weight model so far, while placing it about four months behind US frontier models on a composite cyber index.
  13. OWASP GenAI Security ProjectAgent Control Standard: an open spec for blocking agent actionsINFOToolOWASP GenAI Security ProjectAgent Control Standard: an open spec for blocking agent actionsThe Agent Control Standard is an open specification, now hosted by the OWASP GenAI Security Project, that lets a guardian agent permit, deny or modify an AI agent's tool calls and other actions before they run.
  14. Google Threat Intelligence GroupGoogle GTIG: attackers used AI agents to run a credential campaignINFOIncidentGoogle Threat Intelligence GroupGoogle GTIG: attackers used AI agents to run a credential campaignGoogle Threat Intelligence Group reports a threat actor who planned, built and ran an agent-enabled mass credential harvesting campaign in under six hours. GTIG says it has not yet seen fully autonomous attack pipelines in the wild.
  15. CVE-2026-65669SQL Server Copilot: prompt injection escalates a user to sysadminHIGHVulnerabilityEmbrace The RedSQL Server Copilot: prompt injection escalates a user to sysadminCVE-2026-65669 let indirect prompt injection push GitHub Copilot in SQL Server Management Studio past its read-only mode and run T-SQL with a sysadmin's privileges. Microsoft rates it CVSS 9.6; SSMS 22.8.2 fixes it.
  16. ChatGPT connectorsChatGPT sandbox: shared package cache leaked data across accountsLOWVulnerabilityCheck Point ResearchChatGPT sandbox: shared package cache leaked data across accountsCheck Point Research found that ChatGPT code containers from different accounts shared one internal JFrog Artifactory, giving attackers a hidden channel into a victim's session and connected apps. OpenAI shut the instance down.
  17. AIR SecurityMCPJacking: 155 hijackable servers in the official MCP registryHIGHSupply chainAIR SecurityMCPJacking: 155 hijackable servers in the official MCP registryMCPJacking is an attack on MCP registry entries whose domains have expired. AIR Security found 155 such servers in the official MCP registry, re-registered the domains and gained remote prompt execution on agents that trusted them.