The security intelligence platform for AI teams
AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.
Independent research. No sponsors, no paywalls, no conflicts of interest.
Command Injection Flaw in Ollama-mcp Integration: CVE-2026-19334 affects NightTrek's Ollama-mcp, enabling command injection (execution of unauthorized system commands) via manipulated arguments, though exploitation requires local system access. The vulnerability remains unpatched as developers have not responded to disclosure.
A researcher discovered a vulnerability in Google Gemini where attackers can hide instructions in emails that trick the AI into automatically calling external tools (called Extensions) without the user's knowledge. When a user asks the AI to analyze a malicious email, the AI follows the hidden instructions and invokes the tool, which is a form of request forgery (making unauthorized requests on behalf of the user).