Context Window: AI Security Podcast
Top Story: Prompt Injection Goes Operational — For two years, prompt injection has mostly been a lab demo. ModelScope MS-Agent: a max-severity hole with no fix (CVE-2026-2256). — A command-injection flaw in Alibaba's widely used MS-Agent toolkit lets an attacker run arbitrary commands on the host running the agent (CVSS 9.8). LMDeploy: 13 hours from disclosure to exploitation (CVE-2026-33626). — Earlier this spring, a server-side request forgery flaw in the LMDeploy serving framework — think of it as tricking the server into making requests on the attacker's behalf — went from public advisory to active exploitation in roughly 13 hours, faster than any human patch cycle. CrewAI: four flaws in one agent framework. — The CrewAI orchestration framework picked up four separate vulnerabilities this spring (CVE-2026-2275, -2285, -2286, -2287), catalogued together by CERT/CC (VU#221883). Snowflake buys Natoma to govern what AI agents can touch. — Snowflake (NYSE: SNOW) signed a definitive agreement on May 27 to acquire Natoma, an enterprise platform that secures how AI agents connect to corporate systems through the Model Context Protocol (MCP) — the emerging standard for plugging agents into tools and data. CodeIntegrity raises $5M to put guardrails around agents at runtime. — The seed round (led by Syn Ventures, with Antler and Boost VC) backs a "deterministic control layer" for LLM agents — the idea that because agents behave unpredictably, you wrap them in enforceable, rule-based limits on what they're allowed to do in the moment. EU AI Act: deepfake-labeling rules approach their deadline. — The Act's Article 50 transparency obligations require that AI-generated and manipulated content be labeled or watermarked, with an enforcement window in August 2026. Pentagon formalizes its split with Anthropic. — After designating Anthropic a supply-chain risk in March, the Department of Defense moved in May to source frontier AI from other vendors. Anthropic's vulnerability-hunting AI is finding flaws faster than anyone can patch. — One month into Project Glasswing, Anthropic and roughly 50 partners say its restricted "Mythos" model has uncovered more than 10,000 high- or critical-severity vulnerabilities in the open-source software that underpins the internet — Cloudflare alone found 2,000 bugs, Mozilla fixed 271 in Firefox (about 10× its prior rate), and the UK's AI Security Institute called it the first model to clear both of its multi-step attack simulations end to end. Curated by Asaf Nakash. Voices by AI. Opinions by human. Show notes: https://contextwindowsec.com/episodes/2026-06-01.html
14 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Context Window: AI Security Podcast!