Weekly · News
AI Security — week of 2026-07-06
JadePuffer: AI agent drives an end-to-end ransomware attack
BleepingComputer · 2026-07-04 · corroborated · reporting
JadePuffer is reported as the first ransomware to use an AI agent to automate the full attack chain end to end, raising evasiveness and speed.
Also: The Register Sec · The Hacker News
Cursor AI editor flaws
The Hacker News · 2026-07-01 · single-source · reporting
Cursor AI editor vulnerabilities allow prompt injection to escape sandbox, posing a significant security risk.
AI-Hallucinated Domains
The Hacker News · 2026-07-01 · single-source · reporting
Attackers utilize AI-generated domains for phishing, highlighting the need for enhanced domain validation.
Langflow RCE exploited in the wild
The Hacker News · 2026-06-30 · corroborated · reporting
The Langflow RCE flaw is being actively exploited against AI apps — to deploy Monero miners and as an AI-agent attack vector.
Also: The Hacker News
AI coding agents vulnerable
The Hacker News · 2026-06-30 · single-source · reporting
Decades-old shell trick bypasses safety checks in AI coding agents, demonstrating the need for robust security measures.
iOS AI Apps Leak API Keys
The Hacker News · 2026-06-30 · single-source · reporting
Exposed API keys in iOS AI apps allow unauthorized model requests, highlighting the importance of secure key management.
BioShocking
The Hacker News · 2026-06-30 · single-source · reporting
AI browsers leak credentials via gaming trick, demonstrating the need for enhanced browser security.
Newer models invent fields
Simon Willison · 2026-07-04 · single-source · research
Newer AI models can invent fields, potentially causing tool calls to fail and emphasizing the need for adaptability in AI development.
Poisoned MCP descriptions
The Hacker News · 2026-06-30 · single-source · reporting
AI agents can leak data without triggering alarms through poisoned MCP descriptions, highlighting the importance of robust monitoring.
Claude Fable 5 restored
The Hacker News · 2026-07-01 · single-source · reporting
Jailbreak-linked export controls lifted for Claude Fable 5, potentially impacting the security landscape.
AI assistant jailbroken
The Register Sec · 2026-07-01 · single-source · reporting
Trusted AI assistants can be turned against users, emphasizing the need for robust security measures in AI development.
LLMs vulnerable to prompt injection
The Register Sec · 2026-06-29 · single-source · reporting
Large language models are vulnerable to prompt injection, allowing attackers to trick them into giving sensitive information.