Skip to content

#Security/incidents

0 items today
5/26Tue
  1. Permission Protocol · AI Agent Incident Tracker85

    BadHost CVE-2026-48710: a single-character HTTP Host header injection bypasses Starlette/FastAPI authentication, hitting millions of MCP servers

    X41 D-Sec found CVE-2026-48710 (BadHost): injecting a single character into the HTTP Host header of requests sent to an MCP server or AI agent harness built on Starlette makes the authentication middleware evaluate the wrong path from request.url.path, letting unauthorized access through.

    Why it matters: This post breaks down how the BadHost vulnerability works, its blast radius, and the fixed versions, and explains what an authorization gate does and does not cover.

5/22Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    GitHub confirms 3800 internal repositories were leaked after an employee installed a poisoned Nx Console VS Code extension

    GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.

    Why it matters: The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.

5/21Thu
  1. Permission Protocol · AI Agent Incident Tracker71

    Composio 遭 LLM 生成攻击模式入侵,5,001 个 GitHub token 被窃

    攻击者用 LLM 生成的攻击模式暴力破解漏洞,攻入 Composio 内部智能体监控工具,随后注册恶意工具定义提权到修复系统,在工具执行沙箱中执行任意代码,窃取 5,001 个 GitHub OAuth token,涉及 Gmail、Slack、Notion、Jira、HubSpot、Render、Vercel 等 26 种连接器类型的凭据。

    Awaiting translation

5/20Wed
5/14Thu
  1. Permission Protocol · AI Agent Incident Tracker78

    Microsoft Defender 发现 Mage AI 与 MCP 服务器未鉴权部署,可获 cluster-admin 权限执行 RCE

    Microsoft Defender for Cloud 发现生产环境中的 Mage AI 与 MCP 服务器未启用鉴权,攻击者可执行 shell 命令并获得 cluster-admin 权限,还能窃取同集群工作负载的凭据。

    Awaiting translation

    Why it matters: 材料给出 Mage AI 与 MCP 服务未鉴权部署导致 RCE 的完整链路,可据此检查自家 Helm chart 与 MCP 配置。

5/13Wed
  1. Lovable · Blog22

    Lovable 参与 AIUC-1 认证:为 AI 编程智能体设立安全标准

    Lovable 成为首批寻求 AIUC-1 认证的 AI 编程智能体平台之一,第三方审计计划于 2026 年夏季进行。AIUC-1 是面向 AI 智能体安全、保障与可靠性的标准,此次扩展为首个专为 AI 编程智能体设计的认证框架。该白皮书指出,编程智能体产出源代码、数据库 schema、API 配置等可执行产物,直接接触生产基础设施和真实用户数据,生成代码中的漏洞即是现实的安全暴露。

    Awaiting translation

5/12Tue
  1. Permission Protocol · AI Agent Incident Tracker82

    Claude Code was exploited via a malicious deeplink that injected a SessionStart hook to achieve RCE; fixed in v2.1.118.

    The Claude Code CLI has a critical RCE vulnerability: an attacker can craft a claude-cli:// deeplink to exploit eagerParseCliFlag's context-free parsing of process.argv in main.tsx.

    Why it matters: I walked through the RCE chain caused by Claude Code's lack of contextual parsing for command-line arguments, and gave my take on where the authorization boundary should be drawn.

  2. Permission Protocol · AI Agent Incident Tracker78

    ClaudeBleed:零权限 Chrome 扩展可劫持 Claude 并窃取 Gmail、Drive 和 GitHub 数据

    LayerX 研究人员发现 Claude 的 Chrome 扩展存在信任边界缺陷,任何零权限扩展都能劫持 Claude、绕过用户确认并窃取 Gmail、Google Drive 和 GitHub 数据。

    Awaiting translation

    Why it matters: LayerX 披露的 Claude Chrome 扩展信任边界缺陷,展示了零权限扩展如何绕过确认流程窃取数据。

5/11Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Mini Shai-Hulud 供应链蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ npm/PyPI 包

    TeamPCP 的 Mini Shai-Hulud 蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ 个 npm/PyPI 包,攻击者用 TanStack 的合法 OIDC 身份发布了 84 个恶意 @tanstack/* 版本。

    Awaiting translation

    Why it matters: 复盘了攻击者如何借 GitHub Actions 缓存投毒窃取 OIDC 令牌并写入 Claude Code Hook 实现持久化,可了解供应链攻击的新手法。

5/10Sun
  1. Permission Protocol · AI Agent Incident Tracker80

    Sysdig 记录首例 LLM 智能体后渗透:marimo CVE-2026-39987 到内网数据库泄露不到一小时

    Sysdig TRT 记录了一起由 LLM 智能体驱动的入侵:攻击者利用 marimo 的 CVE-2026-39987 获取云凭证,再用 LLM 智能体通过 Cloudflare Workers 出口池从 AWS Secrets Manager 取回 SSH 密钥,并驱动 8 个并行 SSH 会话在不到两分钟内导出内网 PostgreSQL 数据库。

    Awaiting translation

    Why it matters: 完整还原攻击者用 LLM 智能体在不到一小时内从 marimo RCE 打到内网数据库的链路,可看到后渗透时间被压缩到分钟级。

5/8Fri
  1. Permission Protocol · AI Agent Incident Tracker80

    Claude Code 遭恶意 npm 包经 MCP 中间人劫持窃取 OAuth token

    Mitiga Labs 披露一条针对 Claude Code 的攻击路径:恶意 npm 包通过 postinstall 钩子修改 ~/.claude.json,把 MCP 服务器 URL 替换为攻击者代理,使每次 MCP 会话的 OAuth token 和 SaaS 凭据都经攻击者基础设施转发。

    Awaiting translation

    Why it matters: 披露了恶意 npm 包通过篡改 MCP 配置劫持 OAuth token 的完整攻击链,并指出配置变更缺少授权校验这一根因。

  2. Permission Protocol · AI Agent Incident Tracker82

    Cline AI agent 曝 CVE-2026-44211:未认证 WebSocket 可劫持终端并 RCE

    Cline 的 kanban WebSocket 服务在 localhost 上无认证运行,任意网页可连接 ws://127.0.0.1:3484/api/terminal/io 直接向 Agent 终端 PTY 注入 shell 命令,实现未认证的终端劫持与远程代码执行,CVSS 9.3,影响 v2.13.0 之前所有版本,披露时无补丁。

    Awaiting translation

    Why it matters: CVE-2026-44211 的完整链路与根因拆解,可帮助开发者判断本地 Agent 终端的暴露面。

5/7Thu
  1. Permission Protocol · AI Agent Incident Tracker74

    TrustFall 披露编码智能体安全漏洞:仓库配置可触发一键 RCE

    Adversa AI 发布 TrustFall 研究,指出恶意仓库配置可让编码智能体在通过一次笼统的信任授权后启动攻击者控制的 MCP 服务器,从而在开发者工作站和 CI 环境中造成一键远程代码执行,可能访问本地凭据、仓库内容和工作流密钥。

    Awaiting translation

  2. Permission Protocol · AI Agent Incident Tracker80

    仿冒 OpenAI 仓库在 Hugging Face 登顶热门榜并获 24.4 万次下载后投递窃密木马

    Hugging Face 上一个仿冒 OpenAI Privacy Filter 的仓库登上热门榜第一、获得 244,000 次下载,随后在安装该模型的 Windows 机器上执行窃取凭据的 infostealer。

    Awaiting translation

    Why it matters: 复盘 Hugging Face 上仿冒 OpenAI 仓库的投毒链条,展示热门榜如何被当作信任信号利用。

  3. Permission Protocol · AI Agent Incident Tracker78

    Microsoft Semantic Kernel 提示词注入漏洞可经 eval() 实现主机级远程代码执行

    Microsoft Security 披露 Semantic Kernel 的两个漏洞 CVE-2026-25592 和 CVE-2026-26030,提示词注入可把 AI 模型输出变成主机级远程代码执行。

    Awaiting translation

    Why it matters: 材料梳理了 Semantic Kernel 两个漏洞的成因与补丁版本,可帮助使用该框架的团队判断自身暴露面。

5/4Mon
  1. Permission Protocol · AI Agent Incident Tracker69

    Azure SRE Agent 因未鉴权 WebSocket 向任意 Entra ID 账号暴露实时命令流

    Azure SRE Agent 的 /agentHub SignalR WebSocket 端点因应用注册配置为多租户,接受任意有效 Entra ID token,导致任意租户账号可接收所有实时 Agent 事件,包括用户提示词、推理轨迹、带完整参数的命令、命令输出和排障中出现的部署凭据,对应 CVE-2026-32173(CVSS 8.6)。

    Awaiting translation

4/27Mon
  1. Permission Protocol · AI Agent Incident Tracker83

    AI 编程智能体 9 秒删除 PocketOS 生产数据库及备份

    PocketOS 据报在一次 Railway API 调用中丢失生产数据库和卷级备份,整个过程仅 9 秒,人类来不及介入。事故分析指出危险能力不在代码生成,而在于智能体持有具备生产破坏权限的云厂商令牌;仅靠 PR 门禁看不到绕过代码仓库的直接 Railway API 删除,授权检查应前置到删除生产数据或备份的云厂商 API 调用之前,并要求签名回执写明生产环境、资源、动作和签署人。

    Awaiting translation

    Why it matters: 复盘一次智能体凭令牌直接删除生产库与备份的事故,指出授权检查应放在云厂商 API 调用之前。

4/23Thu
  1. Permission Protocol · AI Agent Incident Tracker85

    OpenClaw: Four Chained CVEs Expose 24.5 Public AI Agent Servers

    Four chained CVEs in OpenClaw affect roughly 24.5 publicly exposed AI agent servers, letting attackers steal credentials, escalate to owner-level gateway control, and plant persistent backdoors on the host.

    Why it matters: Mapping the chained exploitation path across these four CVEs and the missing authorization boundaries helps teams running OpenClaw assess their own exposure.

4/22Wed
  1. Lovable · Blog71

    Lovable 回应 2026 年 4 月安全事件:公开项目聊天记录与源码曾被越权访问

    Lovable 官方回应 2026 年 4 月安全事件:2026 年 2 月 3 日至 4 月 20 日期间,任何持有项目链接的 Lovable 用户都可能访问公开项目的聊天记录和源码,私有项目与 Lovable Cloud 未受影响。

    Awaiting translation

    Why it matters: Lovable 官方复盘公开项目聊天记录与源码被越权访问的完整时间线,并给出产品与流程层面的整改清单。

  2. Permission Protocol · AI Agent Incident Tracker80

    Bitwarden CLI 遭 Shai-Hulud 供应链攻击,定向窃取 Claude Code、Cursor、Codex CLI 的 API Key

    攻击者劫持 Bitwarden 的 CI/CD 流水线,向 npm 发布恶意 @bitwarden/[email protected],在 2026 年 4 月 22 日 5:57–7:30 PM ET 的 90 分钟窗口内被 334 名开发者安装。

    Awaiting translation

    Why it matters: 复盘了恶意 npm 包如何定向窃取 AI 编程工具凭证,并给出 90 分钟窗口与影响范围等可核查细节。

4/19Sun
  1. Permission Protocol · AI Agent Incident Tracker60

    Vercel 称遭黑客入侵致客户数据泄露,源头指向 Context AI 的 OAuth 授权

    Vercel 称此次入侵源自一个连接到企业 Google 账号的 Context AI 应用,攻击者借该 OAuth 路径访问内部系统。TechCrunch 报道称受影响客户的 App 数据和密钥被泄露,Vercel 建议客户轮换部分部署凭证。分析认为 OAuth 授权本应是可审查的生产访问决策,却常被当作一次性同意点击,凭证暴露前应记录应用、scope、数据类别、有效期和签署方。

    Awaiting translation

4/15Wed
  1. Permission Protocol · AI Agent Incident Tracker87

    约翰霍普金斯研究者通过 PR 标题注入从 Claude Code、Gemini CLI 和 GitHub Copilot 窃取 API 密钥

    约翰霍普金斯研究者 Aonan Guan 利用 PR 标题提示词注入,从 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot 中窃取 API 密钥与 GitHub token。

    Awaiting translation

    Why it matters: 约翰霍普金斯研究者用 PR 标题注入从三个 AI 编程智能体中窃取凭据,三家厂商均静默修复并支付漏洞赏金。

4/10Fri
4/4Sat
  1. Hacker News · Prompt Injection52

    PIGuard:通过 MOF 策略缓解提示词注入防护的过度防御

    圣路易斯华盛顿大学与威斯康星大学麦迪逊分校的研究者提出 PIGuard,一个用于检测提示词注入的轻量防护模型,并配套发布 NotInject 评测数据集。NotInject 包含 339 条带触发词的良性样本,用于衡量防护模型的过度防御问题,结果显示现有 SOTA 模型准确率降至接近随机猜测的 60%。

    Awaiting translation

3/31Tue
  1. Martin Alderson74

    Telnyx、LiteLLM 与 axios 供应链攻击:作者主张用移动端式沙箱重构操作系统

    过去一周有攻击者接连投毒多个开源包,从 Trivy 开始,波及 Telnyx(受影响包约 15 万次/周下载)、LiteLLM(约 2200 万次/周)以及 3 月 31 日被攻击的 axios npm 包(至少 1 亿次/周下载),恶意版本会植入木马窃取安装机器的敏感数据。

    Awaiting translation

3/30Mon
3/25Wed
  1. Lovable · Blog22

    Lovable 创始人安全指南:技术尽调看什么,AI 构建的应用如何应对

    Lovable 发布创始人安全指南,梳理技术尽调实际评估的五个领域:数据访问控制、基础设施安全、漏洞管理、依赖与供应链卫生、事件响应与运营成熟度。Lovable 将安全能力嵌入生成流程,AI 安全智能体在代码呈现给用户前独立审查漏洞,代码变更、发布前和后台分析都会自动触发扫描,并在多次重新生成间追踪问题以防回归。

    Awaiting translation

3/24Tue
  1. Permission Protocol · AI Agent Incident Tracker88

    TeamPCP 通过被污染的 Trivy GitHub Action 在 PyPI 投毒 LiteLLM 1.82.7 和 1.82.8

    TeamPCP 通过被污染的 Trivy GitHub Action 劫持 LiteLLM 的 CI/CD 流水线,窃取 PyPI 发布凭证后发布了带后门的 LiteLLM 1.82.7 和 1.82.8。

    Awaiting translation

    Why it matters: 复盘 LiteLLM 被投毒事件的三阶段攻击链与 .pth 持久化机制,可帮助排查自身 CI/CD 与 Kubernetes 风险。

3/23Mon
  1. Hacker News · Prompt Injection20

    Ask HN:没遇到过提示词注入,就说明安全吗?

    一位使用 open claw 的用户在 Hacker News 提问:自己更担心提示词注入而非坏代码,但从未见过有人真的被注入攻击,也没见过终端命令误删全部文件的情况。他认为从演绎上看最坏情况都存在,但从归纳上看从未发生,因此怀疑把 open claw 当成真实安全风险是否理性,并表示要等到 HN 上有人被提示词注入才会真正担心。

    Awaiting translation

3/17Tue
  1. Geoffrey Huntley · Blog22

    Geoffrey Huntley:AI 时代的认知安全与前沿实验室的模型权重操控风险

    Geoffrey Huntley 提出"认知安全"概念,警告人们日常依赖单一前沿实验室的 AI 做决策,等于把认知能力外包给他人。他引用 Anthropic 的 Golden Gate Claude 实验说明,通过修改模型权重可让 Claude 无论对话内容都围绕金门大桥,并推测未来搜索或社交平台可能让广告主竞拍模型权重中的排名。他认为唯一解法是自己训练模型,以保护认知安全、业务运营与供应链。

    Awaiting translation

3/16Mon
  1. Permission Protocol · AI Agent Incident Tracker62

    AI 编码工具误引入存在漏洞的 Next.js 依赖,生产服务器被植入挖矿程序

    一份运营者报告称,AI 辅助编码工具生成的 Next.js 应用固定了一个存在漏洞的依赖,该漏洞随后通过 CVE-2025-29927 被利用。部署后自动化扫描器访问了本应由中间件保护的内部端点,生产服务器上运行起挖矿程序。报告认为,引入已知严重依赖风险的 PR 在发布前应经过审批路径,而运行时利用仍需漏洞扫描和环境隔离。

    Awaiting translation

3/2Mon
  1. Drew Breunig31

    从 Anthropic 与国防部之争看 AI 采购的真正问题:内嵌判断而非使用条款

    Anthropic 与美国国防部之间的争执,核心并非使用条款,而是模型内嵌的判断。作者认为,AI 采购不同于其他技术采购,因为模型带有内嵌视角,军方等大买家会要求审计并影响后训练过程。他认同 Anthropic 的使用红线,并称自己选择 Claude,同时指出这场争论需要冷静展开。

    Awaiting translation

3/1Sun