Newsletter
Read-only holds. Four other things do not.
The failure nobody plans for is attribution. Every action arrives as one service account, and the audit log cannot tell you which agent did what.
Weekly analysis of the threats, vulnerabilities, and defensive innovations shaping AI security. Written for security engineers and CTOs who need signal, not hype.
Recent Issues
Read-only holds. Four other things do not.
The failure nobody plans for is attribution. Every action arrives as one service account, and the audit log cannot tell you which agent did what.
The evaluation environment is the least-monitored production system in the chain.
AISI's agent left public instructions on GitHub telling the next agent how to reuse its accounts. It was never told to deceive anyone.
The best published agent detection rate is 67%. The sensor that buys it reads everything.
The sensor that buys you that number reads every prompt, every tool argument and every tool result on 7,200 employee laptops. The open-source repo ships no r...
An attacker published their agent config. It is your control list, inverted.
Fifteen minutes, thirteen findings on a static personal site. OpenAI's president wants your security team running one of these by Monday.
Read-only held for the entire intrusion. The agent still walked out with a map of the estate.
Anthropic reviewed 141,006 evaluation runs and found three real companies breached. Two of them had no idea until Anthropic called. AWS named read-only as th...
An attacker ran an agent in YOLO mode against a finance ministry. It's the same toggle your developers use.
Researchers caught an autonomous agent enumerating a government network mid-operation, because the attacker left its output directory on the internet. Thirty...
OpenAI's model breached Hugging Face to win a benchmark
17,000 actions over a weekend, and the entire containment failure was one allowlisted package proxy. Then the defenders' commercial AI refused to look at the...
Earlier Issues
- 466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo. Jul 16, 2026
- One polite word bypassed the guardrails. The private repos leaked anyway. Jul 13, 2026
- On July 28, MCP changes shape Jul 04, 2026
- Your agents have no idea who they are. Attackers are counting on it. Jun 27, 2026
- I let an agent rewrite my code while I slept. The scary part wasn't the bill. Jun 20, 2026
- One character in a header bypasses auth on millions of AI servers. Jun 06, 2026
- Your coding agent's approval prompt is lying to you. Jun 04, 2026
- Six governments agree: your AI security model was built for the wrong problem. May 31, 2026
- Claude Mythos, SAFE-MCP, MCPShield: the week the research caught up with the threat. May 20, 2026
- MCP servers just tripled. Here's the full attack map. May 09, 2026
- No caller auth on most MCP servers. CVE-2026-35616 actively exploited. The checklist that closes both gaps. Apr 29, 2026
- 8 agent exploits in Q1. 200,000 vulnerable MCP servers. Anthropic won't fix the protocol. Apr 22, 2026
- Closed Agent Harness = threat model blind spot Mar 30, 2026
- 97% expect an AI agent breach this year Apr 08, 2026
- Trivy compromised. LiteLLM backdoored. Your CI pipeline is the new attack surface. Mar 31, 2026
- 28 out of 30 agent projects. Zero per-agent identity. Zero revocation. Mar 24, 2026
- Three attack papers dropped this week. All point to the same architectural flaw. Mar 16, 2026
- I Red-Teamed My Own Agent Stack, PleaseFix Hijacks Browsers Through Calendar Invites Mar 09, 2026
- Claude Code Supply Chain RCE, AI-Powered FortiGate Blitz, Infostealers Now Harvest AI Agent Souls Mar 02, 2026
- DockerDash MCP Takeover, vLLM CVSS 9.8 RCE, Cisco State of AI Security 2026 Feb 23, 2026
newsletter.aminrj.com
Subscribe to AI Security Intelligence Digest
Weekly analysis of AI security threats, vulnerabilities, and defensive innovations — delivered to your inbox.
Subscribe — it's free