LIVE THREATS
MEDIUM AI Bills of Materials Emerge as Critical Tool for ML Supply Chain Risk // HIGH Anthropic's Claude Mythos Autonomously Uncovers 10,000 Critical Software Flaws // HIGH LLM Coding Agents Collapse Under Structural Constraints, Study Finds // MEDIUM SentinelOne Prompt Security Targets Agentic AI Trust Verification Gap // MEDIUM Google's Gemini Spark Agent Raises Prompt Injection Risks at Enterprise Scale // MEDIUM AI Agent Identity Sprawl Creates New Attack Surface in Enterprise IAM // MEDIUM AI Security Lacks Reliable Measurement: Why Benchmarks Alone Are Insufficient // HIGH Anthropic's Mythos AI Model Used to Find Exploitable macOS Kernel Vulnerability // MEDIUM Microsoft Open-Sources RAMPART and Clarity to Harden AI Agent Security // MEDIUM LLM Activation Steering Goes Local: Security Implications of Direct Model Manipulation //
SUPPLY CHAINSecurityWeekCRITICAL‘By Design’ Flaw in MCP Could Enable AIWidespread Supply Chain Attacks
ATLAS OWASP CRITICAL Active exploitation · Immediate action required SecurityWeek ▲ 9.1

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks

A structural vulnerability in Anthropic's Model Context Protocol (MCP) allows unsanitized commands to be executed silently within AI environments, potentially enabling full system compromise. …

AML.T0010 - ML Supply Chain Compromise AML.T0051 - LLM Prompt Injection AML.T0047 - ML-Enabled Product or Service
LLM SECURITYDark ReadingHIGHMicrosoft, Salesforce Patch AI Agent Data LeakFlaws
ATLAS OWASP HIGH Significant risk · Prioritise patching Dark Reading ▲ 8.2

Microsoft, Salesforce Patch AI Agent Data Leak Flaws

Prompt injection vulnerabilities in Salesforce Agentforce and Microsoft Copilot were patched after researchers demonstrated that external attackers could exploit them to exfiltrate sensitive user …

AML.T0051 - LLM Prompt Injection AML.T0057 - LLM Data Leakage AML.T0047 - ML-Enabled Product or Service