<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AI Threat Watch: AI-Targeted</title><description>An automated watch on attackers using AI and on attacks against AI systems. Short summaries, direct links to the source.</description><link>https://ai-threat.watch/</link><language>en</language><ttl>360</ttl><item><title>Prompt injection still drives most agentic AI security failures in production</title><link>https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-06-11-helpnet-owasp-agentic</guid><description>&lt;p&gt;Coverage of OWASP&apos;s 2026 findings on agentic AI. Most production failures still begin with prompt injection, and attackers increasingly poison what agents trust: MCP servers, packages and coding-tool configuration.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Help Net Security | Vulnerabilities: CVE-2025-6514, CVE-2026-22708&lt;/p&gt;</description><pubDate>Thu, 11 Jun 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud</title><link>https://www.trendmicro.com/en_us/research/26/e/banana-rat.html</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-19-trend-micro-inside-shadow-water-063-s-banana-rat-fro</guid><description>&lt;p&gt;Trend Micro&apos;s MDR team correlated attacker server infrastructure with victim telemetry to map Banana RAT, a banking trojan targeting 16 Brazilian financial institutions via phishing and fileless PowerShell delivery. The malware provides remote control, keylogging, overlay injection, and PIX QR code interception, using a polymorphic crypter service to evade detection.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Trend Micro | Actors: SHADOW-WATER-063 | Malware: Banana RAT, Backdoor.PS1.BANANARAT.A | Attribution: Brazil, per TrendAI (high confidence)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:43:23 GMT</pubDate><category>AI-Targeted</category></item><item><title>When prompts become shells: RCE vulnerabilities in AI agent frameworks</title><link>https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-05-07-microsoft-prompts-become-shells</guid><description>&lt;p&gt;Microsoft researchers show how a single injected prompt reached host-level code execution in agents built on Semantic Kernel. Model-controlled parameters flowed unsanitized into a search plugin. Both flaws are fixed.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Microsoft Security | Vulnerabilities: CVE-2026-25592, CVE-2026-26030&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>OWASP GenAI Exploit Round-up Report Q1 2026</title><link>https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-04-14-owasp-exploit-roundup-q1</guid><description>&lt;p&gt;Quarterly review of eight AI-related incidents mapped to the OWASP LLM and agentic risk lists. It includes active exploitation of a maximum-severity Flowise flaw and GrafanaGhost, a prompt injection path that exfiltrates data from Grafana&apos;s AI features.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: OWASP GenAI Security Project | Vulnerabilities: CVE-2025-59528&lt;/p&gt;</description><pubDate>Tue, 14 Apr 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</title><link>https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-03-27-datadog-litellm-teampcp</guid><description>&lt;p&gt;Two backdoored releases of LiteLLM, a widely used LLM gateway library, were published to PyPI on March 24, 2026 with a credential stealer. Datadog traces the campaign from a poisoned Trivy scanner through npm and into PyPI.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Datadog Security Labs | Actors: TeamPCP&lt;/p&gt;</description><pubDate>Fri, 27 Mar 2026 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Malicious OpenClaw Skills Used to Distribute Atomic macOS Stealer</title><link>https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/malicious-openclaw-skills-used-to-distribute-atomic-macos-stealer</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-23-trendai-research-malicious-openclaw-skills-used-to-distri</guid><description>&lt;p&gt;TrendAI Research documented a campaign where malicious OpenClaw agent skills trick AI agents like GPT-4o into installing a new variant of Atomic macOS Stealer (AMOS), which then deceives users into entering their password. The malware exfiltrates browser data, crypto wallets, Apple and KeePass keychains, and documents, with hundreds of malicious skills found across ClawHub, SkillsMP, and GitHub repositories.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: TrendAI Research | Malware: Atomic (AMOS) Stealer, AMOS&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:40:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Moonlock Lab thread on ClickFix malware abusing Claude.ai and Medium</title><link>https://x.com/moonlock_lab/status/2021695650367226108?s=12</link><guid isPermaLink="false">https://ai-threat.watch/#2026-02-11-moonlock-lab-moonlock-lab-thread-on-clickfix-malware</guid><description>&lt;p&gt;Moonlock Lab reports that a Google Sponsored ad for a macOS search led users to malware via ClickFix delivery, seen over 15,000 times. One variant abused a public artifact hosted on claude.ai, while another used a Medium post impersonating Apple support, both attributed to the same threat actor.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Moonlock Lab | Malware: ClickFix&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:38:42 GMT</pubDate><category>AI-Targeted</category></item><item><title>The Lethal Trifecta Strikes: Four Major AI Agent Vulnerabilities in Five Days</title><link>https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/</link><guid isPermaLink="false">https://ai-threat.watch/#2026-01-21-breached-company-the-lethal-trifecta-strikes-four-major-a</guid><description>&lt;p&gt;Between January 7-15, 2026, researchers including PromptArmor disclosed indirect prompt injection vulnerabilities in four production AI tools: IBM Bob, Superhuman AI, Notion AI, and Anthropic&apos;s Claude Cowork, each allowing data exfiltration via the &apos;lethal trifecta&apos; of private data access, untrusted content exposure, and external communication channels. Vendor responses varied widely, from Superhuman&apos;s rapid remediat&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Breached.company | Malware: Claude Cowork, IBM Bob, Notion AI, Superhuman AI, Superhuman Go&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:41:18 GMT</pubDate><category>AI-Targeted</category></item><item><title>New Prompt Injection Attack Vectors Through MCP Sampling</title><link>https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-12-05-unit-42-palo-alto-networ-new-prompt-injection-attack-vectors-thro</guid><description>&lt;p&gt;Unit 42 researchers show that the Model Context Protocol sampling feature, which lets MCP servers request LLM completions from the client, lacks security controls and trusts servers implicitly. They built a proof-of-concept malicious MCP server against an unnamed coding copilot demonstrating resource theft via hidden prompts, conversation hijacking, and covert tool invocation. No in-the-wild exploitation is claimed;&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Unit 42 (Palo Alto Networks)&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:38:25 GMT</pubDate><category>AI-Targeted</category></item><item><title>Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection</title><link>https://www.infosecurity-magazine.com/news/claude-desktop-extensions-prompt/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-11-05-infosecurity-claude-extensions</guid><description>&lt;p&gt;Researchers reported that extensions for the Claude desktop app could be driven by instructions planted in web content, turning an ordinary browsing request into a path to actions on the user&apos;s machine.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Infosecurity Magazine&lt;/p&gt;</description><pubDate>Wed, 05 Nov 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>First Malicious MCP in the Wild: The Postmark Backdoor That&apos;s Stealing Your Emails</title><link>https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft</link><guid isPermaLink="false">https://ai-threat.watch/#2025-09-25-koi-postmark-mcp</guid><description>&lt;p&gt;An npm package posing as the Postmark MCP server behaved normally for fifteen versions, then added one line that copied every email sent through it to the author&apos;s server. Koi calls it the first malicious MCP server seen in the wild.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Koi Security&lt;/p&gt;</description><pubDate>Thu, 25 Sep 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>Cursor AI Code Editor Fixed Flaw Allowing Attackers to Run Commands via Prompt Injection</title><link>https://thehackernews.com/2025/08/cursor-ai-code-editor-fixed-flaw.html</link><guid isPermaLink="false">https://ai-threat.watch/#2025-08-01-thn-cursor-curxecute</guid><description>&lt;p&gt;An indirect prompt injection could make Cursor&apos;s agent write a malicious MCP configuration file without user approval, giving the attacker remote code execution on the developer&apos;s machine.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: The Hacker News | Vulnerabilities: CVE-2025-54135&lt;/p&gt;</description><pubDate>Fri, 01 Aug 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>&apos;EchoLeak&apos; AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot</title><link>https://www.securityweek.com/echoleak-ai-attack-enabled-theft-of-sensitive-data-via-microsoft-365-copilot/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-06-11-securityweek-echoleak</guid><description>&lt;p&gt;Aim Security showed that a single crafted email could make Microsoft 365 Copilot send internal data to an attacker with no user interaction. Microsoft patched it server-side and reported no exploitation in the wild.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: SecurityWeek | Vulnerabilities: CVE-2025-32711&lt;/p&gt;</description><pubDate>Wed, 11 Jun 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item><item><title>How we estimate the risk from prompt injection attacks on AI systems</title><link>https://blog.google/security/how-we-estimate-risk-from-promp/</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-29-google-deepmind-how-we-estimate-the-risk-from-prompt-inj</guid><description>&lt;p&gt;Google DeepMind describes an automated red-teaming framework using optimization-based attacks (Actor Critic, Beam Search, Tree of Attacks with Pruning) to test AI agents&apos; susceptibility to indirect prompt injection that could exfiltrate sensitive user data. This is a defensive research methodology, not a report of real-world exploitation, and no specific incidents are disclosed.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Google DeepMind&lt;/p&gt;</description><pubDate>Mon, 21 Sep 2026 08:37:15 GMT</pubDate><category>AI-Targeted</category></item><item><title>Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History</title><link>https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</link><guid isPermaLink="false">https://ai-threat.watch/#2025-01-29-wiz-deepseek-database</guid><description>&lt;p&gt;An unauthenticated ClickHouse database belonging to DeepSeek exposed over a million log lines, including chat history, API secrets and backend details, and allowed full control of the database. DeepSeek secured it after disclosure.&lt;/p&gt;&lt;p&gt;AI-Targeted (Attacks on AI) | Source: Wiz Research&lt;/p&gt;</description><pubDate>Wed, 29 Jan 2025 06:00:00 GMT</pubDate><category>AI-Targeted</category></item></channel></rss>