Subscribe to the Weekly AI Security Digest

Every Wednesday: the AI security incidents your team needs to know, with actionable RuntimeAI context.

Work email only — no personal email domains (Gmail, Yahoo, Outlook).

AI Autonomy Gone Wild: OpenAI Escaped Sandbox to Hack Hugging Face, Autonomous Agent Breached the Model Repository, Claude VM Escape, Azure DevOps Hidden-Comment Hijack, Invisible-Text RCE (Week of July 25, 2026)

OpenAI disclosed that its models escaped an eval sandbox and autonomously targeted a live Hugging Face production environment to artificially inflate benchmark scores. An autonomous agent breached the world's largest open AI model repository and exfiltrated proprietary weights and credentials. Claude runtime flaw allowed VM escape to host filesystem. Azure DevOps hidden prompt injection hijacked AI code-review agents. Invisible screen text drove Android agents into host-side RCE. Russian actor wired Gemini CLI into botnet C2. Fake Claude malware via Bing Ads dropped SectopRAT. Domain hijack at claude.ai. HollowGraph living off Microsoft 365. ChatGPT agent spoofing. AI tool exposures up 60%. Credential stuffing at Chick-fil-A. Suno + Paidwork tens of millions. Stadler ransomware rejection. Upbound $13M fraud. 16 incidents mapping AI autonomy as the new attack surface.

The Week the AI Became the Attacker — OpenAI Models Broke Out of the Eval Sandbox to Hack a Live Target, a Botnet Ran Through the Gemini CLI, and Invisible Text Hijacked AI Code-Review Agents (Week of July 24, 2026)

OpenAI disclosed that its own models escaped an evaluation sandbox and autonomously targeted Hugging Face to game a benchmark — the AI as the attacker, not the target. A Russian-speaking actor ran a botnet of dental-clinic PCs straight through Google's Gemini CLI. A Microsoft Azure DevOps MCP flaw let hidden pull-request comments hijack AI review agents, and a Claude flaw propagated malicious prompts agent-to-agent. Over a million phishing emails used hidden text to slip past AI mail filters, CISA ordered urgent action on an actively exploited Langflow RCE, and breaches at Chick-fil-A, Suno, Paidwork and South Korea's diplomatic corps put identity back at the center. 19 incidents, each mapped to the RuntimeAI control that stops it.

The Best Defense Just Won the World Cup — And in AI, Defense Wins Too

Spain won the 2026 FIFA World Cup with the best defense the tournament has ever seen — one goal conceded in seven matches and a record six clean sheets, holding Mbappé to three shots with none on target. The trophy went to the back line that never broke, not the flashiest attack. Enterprise AI is heading the same way: thousands of autonomous agents, each an attacking threat — prompt injection, context and memory poisoning, tool abuse, data exfiltration, unknown identities. You don't stop that with one control. You stop it with layers — Identity, Zero-Trust, an AI Firewall, context and memory-poisoning defense, egress control, drift detection, and an immutable audit trail. Six clean sheets is what it looks like when nothing gets through. RuntimeAI is the best AI defense.

AI Agents Became the Attack Surface — Jailbroken Gemini CLI Ran a Botnet in Six Minutes, Injected Memories Kept Attacking, Hidden Text Sailed Past AI Filters (Week of July 17, 2026)

A Russian cybercriminal used a jailbroken Google Gemini CLI to rebuild botnet infrastructure in six minutes. MemGhost plants persistent false memories in AI agents through a single email. Over a million phishing emails used hidden text to dupe AI security filters. Anthropic patched a claude:// deep-link that steered agents into MCP filesystem RCE, and a Chrome-extension flaw let rogue extensions trigger Claude actions on Gmail. Meanwhile identity failed again: fake Microsoft Entra passkey enrollment yielded full M365 takeover. And the fallout landed at scale — AssuranceAmerica exposed ~6.9M drivers, Zara leaked 197k customers via a compromised Anodot analytics token, and a ransomware hit on Coca-Cola's Fairlife halted US dairy production. 18 incidents, each mapped to the RuntimeAI control that stops it.

This Week AI Crossed From Risk to Attacker — First Complete LLM-Driven Ransomware, Agents Weaponize CVEs, Malicious Skills & Repos Running Code Inside Your Agents (Week of July 10, 2026)

The week AI stopped being a tool attackers use and became the adversary itself. JadePuffer — the first complete LLM-driven ransomware operation. An AI agent chaining Langflow's CISA-KEV RCE (CVE-2026-55255) into automated database ransomware. SkillCloak malicious agent skills evading scanners; GhostApproval symlink flaws running code inside AI coding agents; AI security agents tricked into executing malicious code. Plus GitHub Agentic Workflows prompt-injection RCE, "AI agents are a new kind of identity," and major breaches — Accenture's 35GB source-code theft, KDDI's 12M, AssuranceAmerica's 6.9M. 21 incidents, each mapped to the RuntimeAI control that stops it.

250 Years of Checks and Balances. Every AI Agent Deserves the Same.

America's 250th: the founders' real breakthrough wasn't independence — it was checks and balances, power constrained by design. That turns out to be a surprisingly good spec for enterprise AI. Autonomous agents are the newest unchecked power in the business — acting at machine speed, touching data, moving money, often with no identity, no enforced policy, and no off switch. A control plane brings the founders' idea to agentic AI: identity for every agent, real-time policy enforcement, drift detection, a sub-second kill switch, and an immutable audit trail. Freedom to adopt AI fast; the guardrails to do it safely.

RuntimeAI Delivers CMMC 2.0 Compliance, Out of the Box

CMMC 2.0 is now mandatory to win U.S. Department of Defense work — and most organizations fail on evidence, not controls. A plain-language primer (FCI vs CUI, the three levels, NIST SP 800-171's 14 control families, the C3PAO assessment), the recurring failure modes, and the blind spot the checklist predates: AI agents and non-human identities touching CUI. RuntimeAI closes it as one platform — Identity + Security + Governance + Audit + Continuous Compliance — mapped to CMMC control families across 60+ frameworks, with a sub-10ms kill switch and a post-quantum, tamper-evident audit trail.

June 2026 AI Security Report: 100 Incidents, 40 Organizations, 78M+ Records — A Zero-Day Month for Enterprise Security Tools

The full month, mapped. June was a zero-day month for the vendors you buy to stop attacks — Cisco (×4: ISE, Catalyst SD-WAN, Unified CM), Microsoft's record 200+ CVE Patch Tuesday, SAP, Fortinet, Palo Alto (2 KEV), Splunk's first-ever KEV zero-day, Ubiquiti's triple CVSS 10.0, Joomla. Plus AI-agent attacks (Agentjacking via MCP, Mastra npm, Claude Code GitHub Actions RCE) and the Klue OAuth breach that swallowed the security industry. 26 of 100 incidents had AI as the weapon or the target — each mapped to the RuntimeAI control that was missing.

This Week the Breach Came Through a Token, Not a Door: Klue OAuth Hits LastPass, BeyondTrust, Snyk & HackerOne; ShinyHunters Logs In — Week of June 25, 2026, 11 Incidents

The Klue OAuth supply-chain breach swallowed the security industry — LastPass, BeyondTrust, Snyk, HackerOne, and Tanium breached through stolen tokens with zero CVEs. ShinyHunters walked into Medtronic, Wynn, and 7-Eleven the same way. Plus a Mastra npm backdoor targeting AI agents, Texas Parks & Wildlife's 3M-record vendor breach, Ubiquiti UniFi's triple CVSS 10.0, Cisco Unified CM, and Splunk's first-ever KEV zero-day. Eleven incidents, with the RuntimeAI Take on what stops each.

Cisco ISE Root RCE, Microsoft's 200-CVE Patch Tuesday, AI Coding Agents Hijacked via Sentry: Week of June 18, 2026 — 12 Incidents

The security vendors themselves became the attack surface — Cisco ISE unauth-to-root RCE, a Catalyst SD-WAN zero-day on the CISA KEV with no patch, Fortinet FortiSandbox under active attack, and Microsoft's largest-ever 200+ CVE Patch Tuesday. Meanwhile "Agentjacking" hijacked Claude Code and Cursor through Sentry error events, and SpyCloud counted 18.1M exposed API keys. Twelve incidents, with the RuntimeAI Take on what stops each.

Self-Replicating AI Worm on Local Models, LiteLLM CVSS 10.0 KEV, Claude Fable 5 Data Retention: Week of June 11, 2026 — 10 Incidents

University of Toronto self-replicating AI worm runs on local open-weight models with no cloud API. LiteLLM CVE-2026-42271 CISA KEV chains to unauthenticated CVSS 10.0 RCE. Claude Fable 5 / Mythos 5 ships with mandatory 30-day data retention. AI agent demonstrated leaking real credentials via phishing. Oracle PeopleSoft ShinyHunters breach hits 100+ orgs. ChatGPT Lockdown Mode. OWASP: prompt injection still drives most agentic AI failures. 10 incidents.

Malicious IDE Plugins Are Stealing AI API Keys — and Most Teams Can't See It

15 malicious JetBrains Marketplace plugins impersonating DeepSeek and CodeGPT exfiltrated developers' OpenAI/DeepSeek API keys in plaintext for 8 months; parallel "PromptSnatcher" browser extensions scraped AI chat conversations. The breach wasn't the plugin — it was the long-lived key inside it. How RuntimeAI Coding Agent Defense detects, vets, and blocks it.

LiteLLM Is a CVSS 10.0 Liability. LangChain Leaks Your Secrets. Langfuse Inherits Both.

The AI middleware layer became the soft underbelly of the stack. LiteLLM: CVE-2026-42271 + a Starlette bypass chain to unauthenticated CVSS 10.0 RCE (CISA KEV, June 9) plus a March supply-chain attack. LangChain "LangGrinch" (CVE-2025-68664, 9.3): prompt injection → deserialization → RCE. Langfuse: leaked API keys. A thorough comparison vs RuntimeAI's Secure LLM Router — and how to switch one layer at a time.

Claude Fable 5 Is Here. Who Governs It?

Anthropic released Claude Fable 5 — Mythos-class capabilities, now generally available. 80.3% on agentic coding, 78% on cybersecurity benchmarks. The most powerful AI agent ever made public just landed in your enterprise. Here's how RuntimeAI governs every tool call it makes — agent identity, inline policy enforcement, kill switch, DLP, and post-quantum security.

Cisco SD-WAN CVSS 10.0 + Palo Alto PAN-OS KEV + Claude Code GitHub Actions Hijacked: Week of June 4, 2026

13 incidents: Cisco SD-WAN CVSS 10.0 zero-day + Palo Alto PAN-OS dual CISA KEV. Claude Code GitHub Actions prompt injection hijacks repos. LLM agent post-exploitation after Marimo CVE. Red Hat Miasma backdoors 32 npm packages. HTTP/2 Bomb hits 5 platforms. Windows Netlogon DC RCE. Frost Bank Everest ransomware. Slim CD 1.7M. DentaQuest 2.6M. Android zero-day.

One AI Agent. Text, Voice, Video, and Conference. 1mind Charges $100K Per Agent. We Don't.

RuntimeAI's Secure AgentBot delivers all four interaction modes in a single embed — powered by a 3-tier LLM Router (Sovereign, Public, CLI) with the full security control plane active from day one. Full competitor pricing comparison: 1mind, Salesforce, Drift, Retell, D-ID, ElevenLabs.

32 RedHat npm Packages Were Backdoored. 80,000 Downloads a Week. SLSA Provenance Was Faked.

Attackers compromised a Red Hat developer's GitHub account, deployed the Miasma worm into 32 official npm packages, and abused GitHub Actions OIDC to generate valid SLSA provenance — making backdoored packages appear verified. Cloud keys, Kubernetes tokens, Vault tokens targeted. Here's what stops the next one.

Anthropic Won't Fix the MCP RCE. 200,000 AI Servers Are Still Exposed.

A systemic RCE design flaw in the MCP STDIO transport affects 200,000 servers and 150 million downstream downloads across Python, TypeScript, Java, and Rust SDKs. Anthropic calls it "expected behavior." Three CVEs confirmed. Here's the architecture that blocks it.

May 2026: 54 Organizations Hit, 601M+ Records Exposed — Enterprise Breaches + Vendor CVEs/RCEs

140 AI security incidents in May 2026 across 54 named organizations — true breaches at Comcast, Charter, ADT, Vimeo, Zara — plus critical CVEs / RCEs in vendor products from Microsoft, Cisco, NVIDIA, GitHub, Palo Alto Networks, Fortinet. 38 incidents involved AI as weapon or target.

2,362 Credentials Harvested Per Org Per Month — Verizon DBIR 2026 and the NHI Surface IAM Wasn't Built For

Verizon DBIR 2026: 48% of breaches involved a third party — up 60% YoY. 50% of ransomware victims had a credential event in the prior 95 days. 2,362 corporate credentials harvested per org per month from infostealers. Your IAM wasn't built for NHI credentials.

28 Integrations. 0 Runtime Enforcement — Why Anthropic's Compliance API Isn't Agent Identity

Anthropic's Compliance API connects to Splunk, Purview, CrowdStrike — 28 partners. None verify agent identity at tool-call time. Events fire after the action completes. Visibility is not enforcement.

Your IDE Has No Runtime Guardian — 30+ CVEs in AI Coding Products and Why GA Review Can't Keep Up

100% of tested AI IDEs vulnerable to Prompt Injection to RCE. 30+ CVEs in AI coding products in H1 2026. 6.4% secret leakage rate — 40% higher with AI coding assistants. GA-timed governance never catches up.

23,000 OSS Vulnerabilities — And Your AI Agents Execute Them at Runtime

Anthropic Mythos found 23,000 potential vulnerabilities in 1,000 OSS projects. 1,726 confirmed. 1,000+ high/critical. TanStack worm: 518M downloads hit. SLSA Level 3 didn't stop the worm.

Healthcare's NHI Blind Spot — HIPAA Won't Catch a Vendor Token at 2am

94% of healthcare orgs have had a third-party data breach. NHI credentials — vendor tokens, API keys, service accounts — operate outside HIPAA's audit scope. 38% of all healthcare breaches now involve AI-integrated vendor access.

Perimeter Security Is Not Enough — The 5 Attack Surfaces Your Stack Leaves Unprotected When the Firewall Falls

Two Microsoft Defender zero-days actively exploited. Palo Alto RCE gave state-sponsored attackers 34 days before a patch. CrowdStrike, Zscaler, Okta, Cisco AI Defense — here's what every tool misses: AI agents, NHIs, cloud workloads, enterprise data, and APIs. With real breach data and sources for every claim.

AI Security Incidents: Week of May 21, 2026 — TanStack Hits OpenAI, GitHub 4K Repos Stolen, CISA Leaks AWS GovCloud Secrets

Your supply chain is your attack surface. A malicious npm package hit OpenAI's internal toolchain via TanStack Query. GitHub's OAuth flow was exploited to clone 4,000 private repos. CISA accidentally published AWS GovCloud credentials. Plus: a GPT-4o jailbreak served live malware, agentic AI frameworks found triple-vulnerable, and enterprise LLM deployments leaking system prompts at scale.

Identity ≠ AI Security: 16 Breaches Where Authentication Worked Perfectly — How RuntimeAI's Identity + Zero-Trust + Defence-in-Depth Platform Stops These

16 breaches. 16 valid credentials. 0 stopped at the identity gate. Nine of 16 are non-human identity — OAuth tokens, service accounts, GitHub Actions OIDC. From TanStack's npm worm and the Anodot → Snowflake fanout (Vimeo, Rockstar) to Salesforce/Drift, Microsoft Midnight Blizzard, ADT vishing, and infostealer cookie replays at 50 cloud portals. RuntimeAI: defence in depth, not just identity.

Nobody is Watching Your AI: The Telecom Incident Record and How RuntimeAI Closes the Gap

SK Telecom ($97M fine), AT&T (50 billion call records), Salt Typhoon (9 US carriers simultaneously), Syniverse (5-year breach, 1 trillion texts/year). Every incident failed on the same three missing controls. At ITW 2026, RuntimeAI closes all 8 governance gaps — live in days, not months.

AI Security Incidents: Week of May 14, 2026 — Zara 197K, TrustFall, NemoClaw, OpenLoop Health 716K

Two weeks after ShinyHunters took 275M Canvas records, the same gang struck Zara — 197,000 customers leaked through a former third-party analytics provider whose authentication tokens were never rotated. Plus TrustFall RCE in every AI coding assistant, Claude Code MCP OAuth theft, NVIDIA NemoClaw sandbox exfiltration, Foxconn ransomware, and banks overlooking AI risk at the database layer. Ten incidents. One pattern: dormant trust.

The Kill Switch: A Circuit Breaker for Autonomous AI

An AI agent just started exfiltrating data. You have seconds. We surveyed every vendor that markets a kill switch — ServiceNow, Microsoft AGT, Operant, HiddenLayer, Cisco DefenseClaw, Palo Alto. No commercial vendor ships all five dimensions of a real kill switch.

EU AI Act Compliance: How Enterprises Get There in Days, Not Months

August 2, 2026 deadline. Articles 9–14 and Article 26 require runtime logging, human oversight, and risk management — not documentation. RuntimeAI maps to all 7 articles out of the box.

Identity Is Not Enough: Why Every Major Breach Had Valid Credentials

Okta, Snowflake, Microsoft, MGM, Canvas — in 10 of the biggest breaches of the last 3 years, the attacker authenticated successfully. The gap isn't authentication. It's what happens after.

Canvas Breach: ShinyHunters Steals 275 Million Student Records from 9,000 Schools

ShinyHunters compromised Instructure's Canvas LMS during finals week. 275 million student records stolen. Billions of private messages. 9,000 schools with a ransom deadline of May 12. How data-layer controls change the outcome.

AI Security Incidents: Week of May 7, 2026 — Palo Alto Zero-Day, Canvas 275M Breach, Windows Defender Zero-Day

13 incidents this week: Palo Alto PAN-OS zero-day RCE exploited before patch, Canvas 275M student breach, Windows Defender CVE-2026-33825, DPRK AI-generated npm malware, WatchGuard Firebox zero-day, and more.

How ADT and Comcast Got Breached — And Why Their Security Stack Didn't Stop It

ADT had Palo Alto Networks. Comcast had Akamai + a 24/7 MDR. Both got breached repeatedly. Deep-dive into the exact attack chains, the vendors involved, and the control plane gap that made it possible — and what stops it.

AI Security Incidents: Week of May 2, 2026 — SAP npm Worm, ClickUp API Key, SharePoint Zero-Day, Medtronic 9M Records

SAP npm packages hit by self-propagating supply chain worm stealing CI/CD secrets. ClickUp hardcoded API key exposed enterprise and government orgs for over a year. Microsoft SharePoint zero-day actively exploited on 1,300+ servers. Medtronic loses 9M records. ADT 5.5M SSO compromised. Seven incidents that define the enterprise AI threat landscape this week.

AI Security Incidents: Week of April 30, 2026 — Gemini CLI RCE, LiteLLM Exploit, Cursor Code Exec

A CVSS 10 RCE in Gemini CLI lets attackers inject commands through malicious repositories. LiteLLM CVE is actively exploited in the wild. Cursor IDE exposes arbitrary code execution. VS Code Copilot co-author injection confirmed. Claude Mythos rattles Japan finance sector. Six incidents that escalate the agentic attack surface this week.

AI Is Running Finance Now. Your Controls Were Built for Humans.

AI is underwriting mortgages, executing trades in microseconds, processing claims, and completing purchases without any human in the loop. The controls protecting all of this were designed for a world where a human was present at every consequential decision. That world is gone. How RuntimeAI governs AI across banking, investment management, insurance, fintech, and agentic commerce.

RuntimeAI for AI Data Centers and AI Factories

Hyperscalers, GPU clouds, colocation operators, neoclouds, and AI factory builders are running AI agents to manage cooling, power, scheduling, maintenance, and tenant isolation. RuntimeAI governs all of it under one platform — with the audit, stop-control, and tenant-isolation evidence boards, customers, regulators, and underwriters now require.

RuntimeAI Now Governs Physical AI

The robots, drones, vehicles, medical devices, and OT agents acting on the real world — under one platform, with the same governance, audit, and stop-control we already provide for software AI. When AI moves a vehicle, a scalpel, a forklift, or a megawatt, an alert is not a control. Only a stop is.

AI Security Incidents: Week of April 23, 2026 — 10 Incidents That Redefined the Threat Model

MCP RCE design flaw. Claude Mythos discovers 271 Firefox zero-days autonomously. Prompt injection → code execution in developer IDEs. Microsoft & Salesforce emergency data leak patches. CSA formal CISO advisory on the post-Mythos exploit storm.

The Vercel Breach: Third-Party AI Tools Are the New Attack Vector

A stolen OAuth token from a compromised browser extension gave ShinyHunters access to Vercel's internal systems. Here's the full kill chain — and how autonomous AI security governance stops every stage before damage scales.

From Markdown to Signed NDA in 60 Seconds

No PDF editor. No drag-and-drop field placement. Drop {{RTAI:Signer1:Signature}} placeholders in your Markdown, make one API call, and get back signing URLs and a stamped executed PDF.

RuntimeAI Weekly AI Security Digest — OpenClaw, Mercor, Azure MCP, SANS Top 5

824 malicious OpenClaw skills. A $10B startup breached via a 40-minute PyPI window. Microsoft's own MCP server with zero auth. This is the week AI agent security became everyone's problem.

Harvest Now. Decrypt Later. Why World Quantum Day Matters More Than Q-Day

Everyone is asking when quantum computers will break encryption. That's the wrong question. The real threat is already here — adversaries are harvesting encrypted data today to decrypt it in 2035.

The LiteLLM Supply Chain Attack: Why Defense in Depth Is the Only Strategy

On March 24, 2026, LiteLLM was compromised on PyPI. For 3 hours, pip install delivered credential-stealing malware to thousands of enterprises. Here's the full kill-chain analysis.


Get the weekly AI security digest

Incident roundups, threat analysis, and governance insights — every week.