AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 763
- Last 90 days
- 325
- Change
- +44%vs 225 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 38 |
763 items
Sweet Security Launches Agentic AI Red Teaming to Counter ‘Mythos Moment’
May 13, 2026InfoNewsSecurityIndustrySweet Security has launched Sweet Attack, an agentic AI red teaming product that runs continuous automated attack testing. The agent reasons over a runtime index of each client's own infrastructure, including topology, identity paths and deployed source code, rather than generic models. It also discovers shadow IT and shadow AI components such as MCP servers, and reevaluates attack paths when new components appear.
SecurityWeekMicrosoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
May 13, 2026InfoNewsIndustrySecurityMicrosoft has unveiled MDASH, a multi-model agentic scanning harness that orchestrates more than 100 specialized AI agents to discover, validate, and prove exploitable defects in codebases like Windows. The system has already found 16 vulnerabilities fixed in this month's Patch Tuesday release, including CVE-2026-33824 (CVSS 9.8), a double-free in ikeext.dll reachable by unauthenticated attackers sending crafted packets to machines with IKE version 2 enabled, and CVE-2026-33827 (CVSS 8.1), a race condition in tcpip.sys exploitable via a crafted IPv6 packet on nodes with IPSec enabled. Both flaws can lead to remote code execution. MDASH is in limited private preview with some customers.
The Hacker NewsDefense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark
May 12, 2026InfoNewsSecurityIndustryMicrosoft is announcing a new multi-model agentic scanning harness, codenamed MDASH, for AI-powered cyber defense. The source text is brief and does not describe its benchmark results or further details.
Microsoft Security BlogDefense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark
May 12, 2026InfoNewsSecurityIndustryMicrosoft announced MDASH, its multi-model agentic scanning harness built by the Autonomous Code Security team, which helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack, including four Critical remote code execution flaws in the Windows kernel TCP/IP stack and the IKEv2 service. The harness orchestrates more than 100 specialized AI agents across an ensemble of frontier and distilled models and scored 88.45% on the public CyberGym benchmark, the top score on the leaderboard. MDASH is in limited private preview with a small set of customers.
Microsoft Security BlogExaforce Raises $125 Million for Agentic SOC Platform
May 12, 2026InfoNewsIndustryExaforce, an agentic security operations firm, announced a $125 million Series B round that brings its total funding to $200 million. The round was led by investors including HarbourVest, Peak XV, Mayfield, Khosla Ventures, Seligman Ventures, and AICONIC. The company will use the funds to enhance its agentic SOC platform and expand into Japan and Europe.
SecurityWeekCVE-2026-43993: JunoClaw WAVS bridge server-side request forgery in computeDataVerify
May 12, 2026HighVulnerabilitySecurityCVE-2026-43993CVE-2026-43993 affects JunoClaw, an agentic AI platform built on Juno Network, before 0.x.y-security-1. The WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or resolved IP, which is a server-side request forgery (CWE-918). NIST has not yet provided an NVD assessment.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43992: JunoClaw MCP write tools expose BIP-39 mnemonic in LLM tool-call parameters
May 12, 2026CriticalVulnerabilitySecurityPrivacyCVE-2026-43992CVE-2026-43992 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. Every MCP write tool, including send_tokens, execute_contract, instantiate_contract, upload_wasm and ibc_transfer, accepted 'mnemonic: string' as an explicit tool-call parameter. As a result, the BIP-39 seed was embedded in the LLM tool-call JSON and exposed to any transport, log or telemetry surface between the LLM provider and the MCP process.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43991: JunoClaw plugin-shell safety check bypass enables host command execution
May 12, 2026HighVulnerabilitySecurityCVE-2026-43991CVE-2026-43991 affects JunoClaw, an agentic AI platform built on Juno Network, before 0.x.y-security-1. A substring-based blocklist in the plugin-shell command-safety check, applied to the raw command string rather than the parsed first token, can be bypassed by adversarial argument constructions. When combined with the companion advisory, this allows unauthorized command execution on the host.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43990: JunoClaw plugin-shell command injection through run_command arguments
May 12, 2026HighVulnerabilitySecurityCVE-2026-43990CVE-2026-43990 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The plugin-shell run_command function wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell parser, so shell metacharacters in agent-supplied arguments were interpreted as command syntax. The issue is classified as CWE-77 and CWE-78, and NVD published it on 05/12/2026.
Fix: This vulnerability is fixed in 0.x.y-security-1.
NVD/CVE DatabaseCVE-2026-43989: JunoClaw upload_wasm MCP tool accepts unvalidated filesystem paths
May 12, 2026HighVulnerabilitySecurityCVE-2026-43989CVE-2026-43989 affects JunoClaw, an agentic AI platform built on Juno Network, prior to 0.x.y-security-1. The upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes that path resolved to, without validating location, symlink target, file size, or file format. The flaw is classified as CWE-20, CWE-22, CWE-59 and CWE-73.
Fix: Fixed in 0.x.y-security-1.
NVD/CVE DatabaseWhy Agentic AI Is Security's Next Blind Spot
May 12, 2026InfoNewsSecurityIndustryThe article argues that security teams lack fluency in agentic AI, which is already running in production across many organizations, and that this gap is widening. It describes three agent categories: general-purpose coding agents such as Claude Code and GitHub Copilot, vendor-built agents using the Model Context Protocol (MCP), and custom agents built by individual users. It illustrates MCP risk with a malicious calendar invite whose hidden instructions an agent reads and executes.
The Hacker News8 guiding principles for reskilling the SOC for agentic AI
May 11, 2026InfoNewsIndustryPolicyDXC Technology's global CISO Mike Baker has built one of the largest agentic security operation centers in the world and embedded experts from agentic SOC vendor 7AI in his teams to upskill staff. Other leaders, including Damon McDougald at Accenture and John White, have retrained teams through hands-on bootcamps or hands-off experimentation with new agentic AI tools.
CSO Online1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolution
May 11, 2026MediumNewsSecurityIndustryKnostic researchers found 1,862 MCP servers exposed to the public internet, and in a manual check of 119 instances every one allowed unauthenticated access to internal tool listings. Some exposed production systems had write access to financial databases, social media accounts and CRM platforms. The article also covers EchoLeak (CVE-2025-32711), a zero-click exploit disclosed by Aim Security in June 2025, and CVE-2025-6514 in the mcp-remote package, which JFrog disclosed in July 2025.
CSO OnlineSBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation
May 9, 2026InfoResearchPeer-reviewedSecurityResearchACM Digital Library (TOPS, DTRAP, CSUR)CVE-2026-44286: FastGPT unauthenticated SSRF through lafModule fetchData in workflow node
May 8, 2026HighVulnerabilitySecurityCVE-2026-44286CVE-2026-44286 affects FastGPT, an AI Agent building platform, prior to version 4.14.17. An unauthenticated attacker, or an authenticated user with App editing privileges, can make the fetchData function in the lafModule workflow node send arbitrary HTTP requests to internal or private network addresses. The function uses axios on user-controlled URLs without checking them against the isInternalAddress blocklist guard.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseCVE-2026-44284: FastGPT SSRF through stored internal MCP tool server URLs
May 8, 2026MediumVulnerabilitySecurityCVE-2026-44284FastGPT, an AI Agent building platform, prior to version 4.14.17, let authenticated users who can create or manage MCP toolsets save an internal MCP server URL, such as http://localhost:3000/mcp, through the MCP tool create and update endpoints. The direct MCP preview and run endpoints already rejected internal or private network URLs, so the protection was inconsistent. Later workflow execution used the stored URL without revalidating the destination, letting the FastGPT backend workflow runner connect to that internal destination.
Fix: Fixed in 4.14.17.
NVD/CVE DatabaseCVE-2026-42345: FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in…
May 8, 2026HighVulnerabilitySecurityCVE-2026-42345FastGPT versions 4.14.11 and prior are affected by CVE-2026-42345. The isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints with a fullUrl.startsWith() check against a hardcoded list, which at least 7 URL encoding techniques bypass to reach the same metadata service. The broader private IP check is disabled by default because CHECK_INTERNAL_IP defaults to false.
NVD/CVE DatabaseCVE-2026-42344: FastGPT DNS rebinding in isInternalAddress() allows internal address bypass
May 8, 2026MediumVulnerabilitySecurityCVE-2026-42344CVE-2026-42344 affects FastGPT, an AI Agent building platform, in versions 4.14.11 and prior. The isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding, a time-of-check to time-of-use flaw: it resolves the hostname with dns.resolve4()/dns.resolve6() and checks the IPs against private ranges, but the HTTP request runs as a separate call with a new DNS resolution, so the record can change between validation and fetch.
NVD/CVE DatabaseCVE-2026-42343: FastGPT code-sandbox denial of service through unrestricted resource consumption
May 8, 2026MediumVulnerabilitySecurityCVE-2026-42343CVE-2026-42343 affects FastGPT, an AI Agent building platform, in versions 4.14.13 and prior. Its code-sandbox component relies only on an application-level soft limit, a 500ms polling interval, for memory management and lacks OS-level constraints such as cgroups or kernel-level namespaces. Attackers can bypass memory checks through time-window attacks or exhaust the JavaScript worker pool with concurrent CPU-intensive requests, causing a complete Denial of Service for legitimate users.
NVD/CVE DatabaseCVE-2026-42302: FastGPT agent-sandbox unauthenticated remote code execution via code-server
May 8, 2026CriticalVulnerabilitySecurityCVE-2026-42302FastGPT, an AI Agent building platform, has an unauthenticated Remote Code Execution flaw in its agent-sandbox component from version 4.14.10 to before 4.14.13. The startup script entrypoint.sh runs code-server with the --auth none flag and binds it to 0.0.0.0:8080, so any user with network access to that port can bypass authentication and gain full control of the sandbox environment.
Fix: Fixed in 4.14.13.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.