LIVE THREATS
MEDIUM AI Bills of Materials Emerge as Critical Tool for ML Supply Chain Risk // HIGH Anthropic's Claude Mythos Autonomously Uncovers 10,000 Critical Software Flaws // HIGH LLM Coding Agents Collapse Under Structural Constraints, Study Finds // MEDIUM SentinelOne Prompt Security Targets Agentic AI Trust Verification Gap // MEDIUM Google's Gemini Spark Agent Raises Prompt Injection Risks at Enterprise Scale // MEDIUM AI Agent Identity Sprawl Creates New Attack Surface in Enterprise IAM // MEDIUM AI Security Lacks Reliable Measurement: Why Benchmarks Alone Are Insufficient // HIGH Anthropic's Mythos AI Model Used to Find Exploitable macOS Kernel Vulnerability // MEDIUM Microsoft Open-Sources RAMPART and Clarity to Harden AI Agent Security // MEDIUM LLM Activation Steering Goes Local: Security Implications of Direct Model Manipulation //
Human Trust of AI Agents
ATLAS OWASP MEDIUM Moderate risk · Monitor closely Schneier on Security ▲ 6.2

Human Trust of AI Agents

Research published via Schneier on Security reveals that humans systematically over-trust LLMs in strategic game environments, defaulting to Nash-equilibrium rational play based on assumptions of LLM …

AML.T0047 - ML-Enabled Product or Service AML.T0043 - Craft Adversarial Data
SUPPLY CHAINSecurityWeekCRITICAL‘By Design’ Flaw in MCP Could Enable AIWidespread Supply Chain Attacks
ATLAS OWASP CRITICAL Active exploitation · Immediate action required SecurityWeek ▲ 9.1

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks

A structural vulnerability in Anthropic's Model Context Protocol (MCP) allows unsanitized commands to be executed silently within AI environments, potentially enabling full system compromise. …

AML.T0010 - ML Supply Chain Compromise AML.T0051 - LLM Prompt Injection AML.T0047 - ML-Enabled Product or Service
AGENTIC AISecurityWeekMEDIUMCapsule Security Emerges From Stealth With $7Million in Funding
ATLAS OWASP MEDIUM Moderate risk · Monitor closely SecurityWeek ▲ 6.5

Capsule Security Emerges From Stealth With $7 Million in Funding

Capsule Security, an Israeli startup, has emerged from stealth with $7 million in seed funding focused on runtime security for AI agents, continuously monitoring their behaviour to detect and prevent …

AML.T0051 - LLM Prompt Injection AML.T0047 - ML-Enabled Product or Service AML.T0057 - LLM Data Leakage
LLM SECURITYDark ReadingHIGHMicrosoft, Salesforce Patch AI Agent Data LeakFlaws
ATLAS OWASP HIGH Significant risk · Prioritise patching Dark Reading ▲ 8.2

Microsoft, Salesforce Patch AI Agent Data Leak Flaws

Prompt injection vulnerabilities in Salesforce Agentforce and Microsoft Copilot were patched after researchers demonstrated that external attackers could exploit them to exfiltrate sensitive user …

AML.T0051 - LLM Prompt Injection AML.T0057 - LLM Data Leakage AML.T0047 - ML-Enabled Product or Service
RESEARCHSchneier on SecurityMEDIUMHow Hackers Are Thinking About AI
ATLAS OWASP MEDIUM Moderate risk · Monitor closely Schneier on Security ▲ 6.2

How Hackers Are Thinking About AI

A new academic paper analysed over 160 cybercrime forum conversations to understand how threat actors are discussing and adopting AI tools for criminal purposes. The research documents both misuse of …

AML.T0047 - ML-Enabled Product or Service AML.T0054 - LLM Jailbreak AML.T0051 - LLM Prompt Injection