Subscribe to AI Security Weekly

Every Wednesday: the AI security incidents your team needs to know, with actionable RuntimeAI context.

Work email only โ€” no personal email domains (Gmail, Yahoo, Outlook).

AI Security Incidents: Week of May 7, 2026 โ€” Palo Alto Zero-Day, Canvas 275M Breach, Windows Defender CVE

13 incidents: Palo Alto PAN-OS zero-day RCE exploited before patch, Canvas 275M student breach during finals week, Windows Defender CVE-2026-33825, DPRK AI-generated npm malware, WatchGuard Firebox zero-day, and 1 million exposed AI service endpoints with no auth.

AI Security Incidents: Week of May 2, 2026 โ€” SAP npm Worm, ClickUp API Key, SharePoint Zero-Day, Medtronic 9M Records

SAP npm packages hit by self-propagating supply chain worm stealing CI/CD secrets. ClickUp hardcoded API key exposed enterprise and government orgs for over a year. Microsoft SharePoint zero-day actively exploited on 1,300+ servers. Medtronic loses 9M records. ADT 5.5M SSO compromised.

AI Security Incidents: Week of April 30, 2026 โ€” Gemini CLI RCE, LiteLLM Exploit, Cursor Code Exec

CVSS 10 RCE in Gemini CLI lets attackers inject commands through malicious repositories. LiteLLM CVE actively exploited in the wild. Cursor IDE exposes arbitrary code execution. VS Code Copilot co-author injection confirmed. Six incidents that escalate the agentic attack surface.

AI Security Incidents: Week of April 23, 2026 โ€” 10 Incidents That Redefined the Threat Model

MCP RCE design flaw. Claude Mythos discovers 271 Firefox zero-days autonomously. Prompt injection โ†’ code execution in developer IDEs. Microsoft & Salesforce emergency data leak patches. CSA formal CISO advisory on the post-Mythos exploit storm.

RuntimeAI Weekly AI Security Digest โ€” OpenClaw, Mercor, Azure MCP, SANS Top 5

824 malicious OpenClaw skills. A $10B startup breached via a 40-minute PyPI window. Microsoft's own MCP server with zero auth. This is the week AI agent security became everyone's problem.


Get AI Security Weekly in your inbox

Incident roundups, threat analysis, and governance insights โ€” every Wednesday.