Newsletter
466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo.
Alberta reviewed 466M lines of code with 50 Claude agents in 20 hours. Two hackers shipped a profitable autonomous hackbot. And agent identity became something you can buy. One thread ties all three.
Weekly analysis of the threats, vulnerabilities, and defensive innovations shaping AI security. Written for security engineers and CTOs who need signal, not hype.
Recent Issues
466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo.
Alberta reviewed 466M lines of code with 50 Claude agents in 20 hours. Two hackers shipped a profitable autonomous hackbot. And agent identity became somethi...
One polite word bypassed the guardrails. The private repos leaked anyway.
GitHub's agentic workflows leaked private repos to anyone who could open an issue. An AI agent ran a ransomware attack nearly end to end. And Kubernetes ops ...
On July 28, MCP changes shape
The new MCP spec goes final July 28 and moves security from the protocol to the endpoint. Plus: new research explains why prompt injection works, and it's no...
Your agents have no idea who they are. Attackers are counting on it.
Identiverse 2026 named agent identity the defining problem of the year. Step Finance lost $27M because its agents could move money without asking. The fix is...
I let an agent rewrite my code while I slept. The scary part wasn't the bill.
OWASP's agentic security report now reads like an incident log, not a threat catalog. The same permission model powering autonomous coding loops is the one a...
One character in a header bypasses auth on millions of AI servers.
BadHost breaks path-based auth in Starlette — FastAPI, vLLM, LiteLLM, and every MCP server built on them. 325M weekly downloads. The patch is one line. The f...
Earlier Issues
- Your coding agent's approval prompt is lying to you. Jun 04, 2026
- Six governments agree: your AI security model was built for the wrong problem. May 31, 2026
- Claude Mythos, SAFE-MCP, MCPShield: the week the research caught up with the threat. May 20, 2026
- MCP servers just tripled. Here's the full attack map. May 09, 2026
- No caller auth on most MCP servers. CVE-2026-35616 actively exploited. The checklist that closes both gaps. Apr 29, 2026
- 8 agent exploits in Q1. 200,000 vulnerable MCP servers. Anthropic won't fix the protocol. Apr 22, 2026
- Closed Agent Harness = threat model blind spot Mar 30, 2026
- 97% expect an AI agent breach this year Apr 08, 2026
- Trivy compromised. LiteLLM backdoored. Your CI pipeline is the new attack surface. Mar 31, 2026
- 28 out of 30 agent projects. Zero per-agent identity. Zero revocation. Mar 24, 2026
- Three attack papers dropped this week. All point to the same architectural flaw. Mar 16, 2026
- I Red-Teamed My Own Agent Stack, PleaseFix Hijacks Browsers Through Calendar Invites Mar 09, 2026
- Claude Code Supply Chain RCE, AI-Powered FortiGate Blitz, Infostealers Now Harvest AI Agent Souls Mar 02, 2026
- DockerDash MCP Takeover, vLLM CVSS 9.8 RCE, Cisco State of AI Security 2026 Feb 23, 2026
newsletter.aminrj.com
Subscribe to AI Security Intelligence Digest
Weekly analysis of AI security threats, vulnerabilities, and defensive innovations — delivered to your inbox.
Subscribe — it's free