Posts Tagged ‘AI Security’
LiteLLM MCP Authentication Bypass: Patch Now
A LiteLLM MCP authentication bypass, CVE-2026-59822 (CVSS 8.8), lets an attacker skip OAuth2 login entirely when connecting to Model Context Protocol servers through LiteLLM’s proxy, gaining whatever access an authenticated session would carry. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, the first MCP-related vulnerability ever listed there; WatchTowr reports…
Read MoreJuly 2026 Cybersecurity Roundup: A Rogue AI Agent, Ransomware Disruption, and Critical CVEs
This July 2026 Cybersecurity Roundup lands in a month when the peak of northern-hemisphere summer brought no letup in cyber incidents — if anything, July produced some of the year’s most unusual attacks so far. Here’s a roundup of the month’s key incidents and newly disclosed vulnerabilities, along with our take on what they mean.…
Read MoreRuflo RufRoot CVE-2026-59726: AI Agents Hijacked
Ruflo RufRoot CVE-2026-59726, a maximum-severity CVSS 10.0 flaw disclosed by Noma Security, lets an unauthenticated attacker take full control of an AI agent platform used by an estimated one million people — through a single HTTP request against a management bridge that ships exposed to the network by default. What Happened Ruflo is an open-source…
Read MoreTop 5 Cybersecurity News Stories July 10, 2026
The five stories in this week’s Cybersecurity News Stories July 10, 2026 share a structural property: in each case, the system that was compromised or weaponised is one that the organisation had placed into a category other than “security risk.” An AI workflow orchestration platform is operational infrastructure for teams experimenting with automation — it…
Read MoreJADEPUFFER Agentic AI Ransomware Attack
JADEPUFFER agentic AI ransomware is, according to Sysdig’s Threat Research Team, the first publicly documented case of a ransomware attack executed start to finish by an autonomous AI agent — from initial access through a Langflow vulnerability to database encryption and extortion, with no human operator directing any step. What Happened Sysdig identified JADEPUFFER, this…
Read More
