AI agents
Systems in which a model plans and takes actions through tools, browsers or other software on someone's behalf.
- All items
- 764
- Last 90 days
- 325
- Change
- +44%vs 226 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 3 |
| Jun 2025 | 4 |
| Jul 2025 | 4 |
| Aug 2025 | 5 |
| Sep 2025 | 11 |
| Oct 2025 | 6 |
| Nov 2025 | 3 |
| Dec 2025 | 8 |
| Jan 2026 | 10 |
| Feb 2026 | 49 |
| Mar 2026 | 89 |
| Apr 2026 | 51 |
| May 2026 | 76 |
| Jun 2026 | 78 |
| Jul 2026 | 112 |
| Aug 2026 | 78 |
| Sep 2026 | 133 |
| Oct 2026 | 39 |
764 items
CVE-2026-39861: Claude Code sandbox escape through symlinks outside the workspace
Apr 20, 2026HighVulnerabilitySecurityCVE-2026-39861Claude Code versions before 2.1.64 let sandboxed processes create symlinks pointing outside the workspace. When Claude Code later wrote through such a symlink, its unsandboxed process followed it and wrote to the external target without asking the user for confirmation, enabling a sandbox escape that could potentially lead to code execution outside the sandbox. Exploitation required injecting untrusted content into the Claude Code context window to trigger sandboxed code execution.
Fix: Fixed in version 2.1.64. Users on standard auto-update received the fix automatically; users performing manual updates are advised to update to version 2.1.64 or later.
NVD/CVE DatabaseSiIicon Valley's AI agent hiccups: Wasted tokens and 'chaotic' systems
Apr 19, 2026InfoNewsIndustrySecurityExecutives and engineers at two Silicon Valley AI events said building and running AI agents remains difficult and costly. Kevin McGrath, CEO of Meibel, warned that routing every task through a large language model wastes tokens, while Google engineer Deep Shah focused on managing the inference costs of large agent fleets. ThinkingAI co-founder Chris Han said OpenClaw is too complicated and too prone to security flaws for enterprise use.
CNBC TechnologyCVE-2026-40352: FastGPT NoSQL injection in password change endpoint
Apr 17, 2026HighVulnerabilitySecurityCVE-2026-40352FastGPT, an AI Agent building platform, has a NoSQL injection flaw in its password change endpoint in versions prior to 4.14.9.5. An authenticated attacker can inject MongoDB query operators to bypass the "old password" check, changing the password of their own account or others' accounts when combined with ID manipulation, which leads to full account takeover and persistence.
Fix: Fixed in version 4.14.9.5.
NVD/CVE DatabaseCVE-2026-40351: FastGPT NoSQL injection in password-based login endpoint
Apr 17, 2026CriticalVulnerabilitySecurityCVE-2026-40351CVE-2026-40351 affects FastGPT, an AI Agent building platform, in versions prior to 4.14.9.5. The password-based login endpoint uses TypeScript type assertion without runtime validation, so an unauthenticated attacker can submit a MongoDB query operator object such as {"$ne": ""} as the password field. This NoSQL injection bypasses the password check and allows login as any user, including the root administrator.
Fix: This issue has been fixed in version 4.14.9.5.
NVD/CVE DatabaseRCE by design: MCP architectural choice haunts AI agent ecosystem
Apr 16, 2026MediumNewsSecuritySafetyOX Security researchers report that the STDIO transport in Anthropic's MCP reference implementation lets client applications pass arbitrary commands to StdioServerParameters, which execute with the parent process's permissions, exposing systems to remote code execution. Anthropic, LangChain and FastMCP maintain this is by design and that client developers must sanitize MCP configurations. The researchers say they executed commands on six official services and took over thousands of public servers across more than 200 open-source GitHub projects.
CSO OnlineCodex for (almost) everything
Apr 16, 2026InfoNewsIndustryOpenAI released a major update to Codex, its coding agent used by more than 3 million developers weekly. The update adds background computer use, where multiple agents can operate Mac apps in parallel by seeing, clicking and typing with their own cursor, plus an in-app browser, image generation with gpt-image-1.5, memory of user preferences, and more than 90 plugins that combine skills, app integrations and MCP servers.
OpenAI BlogMicrosoft, Salesforce Patch AI Agent Data Leak Flaws
Apr 15, 2026MediumNewsSecurityPrivacyTwo prompt injection flaws in Salesforce Agentforce and Microsoft Copilot could have let an external attacker leak sensitive data. Both have since been fixed.
Dark ReadingDeterministic + Agentic AI: The Architecture Exposure Validation Requires
Apr 15, 2026InfoNewsIndustrySecurityPentera's AI Security and Exposure Report 2026 says every surveyed CISO reports AI already in use across their organizations. The article argues that security validation needs AI for adaptive testing, but that fully agentic systems, where AI reasoning governs execution end to end, undermine the repeatability that structured security programs require. It proposes a hybrid model in which deterministic logic defines attack chain execution and AI adapts payloads within that structure.
The Hacker NewsFinBot CTF Is Live: A Hands-On Companion to the OWASP GenAI Security Project
Apr 15, 2026InfoResearchIndustrySecurityResearchFinBot is a hands-on agentic AI capture-the-flag platform from the OWASP GenAI Security Project's Agentic Security Initiative, described as the "Juice Shop for Agentic AI." It simulates a multi-agent vendor management platform with LLM-driven onboarding, fraud detection, invoice processing and communications, and its challenges map to the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, CWE and MITRE ATLAS. The source positions it as a companion to the Agentic Top 10 framework rather than a replacement.
OWASP GenAI SecurityCurity looks to reinvent IAM with runtime authorization for AI agents
Apr 14, 2026InfoNewsSecurityIndustrySwedish vendor Curity announced Access Intelligence, an extension to its Identity Server API IAM platform, to secure autonomous AI agents. Its approach treats agents as a special type of application, issuing OAuth tokens that carry the agent's purpose and intent, with access granted per action at runtime rather than through static permissions.
CSO OnlineSecure AI agent access patterns to AWS resources using Model Context Protocol
Apr 14, 2026InfoNewsSecurityIndustryThis AWS blog post explains how to secure AI agents and coding assistants that access AWS resources through the Model Context Protocol (MCP). It argues that agents can do anything their granted entitlements allow, so IAM permissions must be designed as deterministic controls, and it presents three IAM security principles with policy examples.
AWS Security BlogEnterprises power agentic workflows in Cloudflare Agent Cloud with OpenAI
Apr 13, 2026InfoNewsIndustryCloudflare is making OpenAI frontier models, including GPT-5.4, available to millions of customers within Agent Cloud, a platform for deploying AI agents that handle tasks such as responding to customers, updating systems and generating reports. The Codex harness is now generally available in Cloudflare Sandboxes and will come to Workers AI in the near future.
OpenAI BlogCVE-2026-40252: FastGPT broken access control lets teams run other teams' applications
Apr 10, 2026MediumVulnerabilitySecurityCVE-2026-40252CVE-2026-40252 is a Broken Access Control flaw (IDOR/BOLA) in FastGPT, an AI Agent building platform, affecting versions prior to 4.14.10.4. Any authenticated team can supply a foreign appId to access and execute another team's applications, because the API validates the team token but does not check that the application belongs to that team. The result is cross-tenant data exposure and unauthorized execution of private AI workflows.
Fix: Fixed in 4.14.10.4.
NVD/CVE DatabaseCVE-2026-40100: FastGPT server-side request forgery in the mcpTools/runTool endpoint
Apr 10, 2026MediumVulnerabilitySecurityCVE-2026-40100CVE-2026-40100 affects FastGPT, an AI Agent building platform, prior to 4.14.10.3. The /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication, and the internal IP check in isInternalAddress() blocks private IPs only when CHECK_INTERNAL_IP=true, which is not the default. Unauthenticated attackers can therefore perform SSRF against internal network resources.
Fix: Fixed in 4.14.10.3.
NVD/CVE DatabaseThe agentic SOC—Rethinking SecOps for the next decade
Apr 9, 2026InfoNewsIndustrySecurityMicrosoft describes the agentic SOC, a security operations model that moves from reacting to incidents toward anticipating attacker movement and reshaping the environment to cut off their paths. The model pairs a threat protection platform with built-in autonomous defense and AI agents that assist analysts with investigation and prioritization. The article is the opening of a series and points to a new whitepaper, The agentic SOC: Your teammate for tomorrow, today.
Microsoft Security BlogCVE-2026-39981: AGiXT path traversal in safe_join() of essential_abilities extension
Apr 9, 2026HighVulnerabilitySecurityCVE-2026-39981CVE-2026-39981 affects AGiXT, an AI Agent Automation Platform, before version 1.9.2. The safe_join() function in the essential_abilities extension does not check that resolved file paths stay within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT instance.
Fix: Fixed in 1.9.2.
NVD/CVE DatabaseMicrosoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
Apr 8, 2026InfoNewsSecurityIndustryMicrosoft has released the Agent Governance Toolkit, an open-source project that monitors and controls AI agents during execution. It adds a runtime security layer that enforces policies against issues such as prompt injection and maps to OWASP's top 10 risks for agentic systems. The toolkit is in public preview under an MIT license, with components in Python, TypeScript, Rust, Go and .NET.
CSO OnlineSBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation
Apr 7, 2026InfoResearchPeer-reviewedSecurityResearchThe source text is a bibliographic citation for an article titled "SBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation," published in Digital Threats: Research and Practice, Volume 7, Issue 2, pages 1-35, June 2026. It contains no abstract, method, or findings, so the research question and results cannot be stated from this text.
ACM Digital Library (TOPS, DTRAP, CSUR)The New Rules of Engagement: Matching Agentic Attack Speed
Apr 7, 2026InfoNewsSecurityIndustryThe source argues that the cybersecurity response to AI-enabled nation-state threats cannot be incremental and must instead be architectural. It is a short opinion piece with no further details on specific attacks, products or figures.
SecurityWeekFlowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
Apr 7, 2026MediumNewsSecurityIndustryThreat actors are exploiting CVE-2025-59528 (CVSS 10.0), a code injection flaw in Flowise's CustomMCP node that executes user-supplied JavaScript in the mcpServerConfig string without validation. Successful exploitation allows access to child_process and fs, leading to full system compromise, according to VulnCheck. VulnCheck reports 12,000+ exposed Flowise instances, and the flaw was publicly known for more than six months.
Fix: The issue was addressed in version 3.0.6 of the npm package.
The Hacker News
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.