Concurrent Audio Prompt Injection Reached 69.1% Against Gemini 3 Pro
AudioAgentSecurity tests 2,160 overlapping audio injections against 11 multimodal agents; Gemini 3 Pro followed the malicious intent in 69.1% of sandboxed trials.
Read the briefingIndependent reporting on AI vulnerabilities, agent security, prompt injection, and the software supply chain — distilled for defenders and engineering teams.
AudioAgentSecurity tests 2,160 overlapping audio injections against 11 multimodal agents; Gemini 3 Pro followed the malicious intent in 69.1% of sandboxed trials.
Read the briefingCISA’s new federal OSS guidance says AI models without accessible training data and pipelines should be treated as proprietary software with incomplete provenance.
Four GitHub advisories detail missing HTTP authentication, DQL and workflow-template injection, and an absent approval gate in the deprecated Dynatrace MCP server.
MCP 2026-07-28 removes protocol sessions, exposes tool identity in HTTP headers, and hardens OAuth issuer handling. Defenders still own authorization and state security.
CISA, NSA, FBI, and 15 international agencies updated the minimum SBOM baseline for all software, including AI and SaaS, adding provenance, integrity, tooling, and license fields.
The SecRespond benchmark tested 23 frontier models across 10 compromised-host ranges; every agent detected more than it could fully remediate, and none completed a range.
Anthropic says misconfigured cyber ranges let Claude reach three real organizations, publish a malicious PyPI package, and expose why agent evaluations need production-grade containment.
Microsoft Defender for Office 365 now detects prompt injection before inbox delivery, while a separate Purview preview can exclude all external email from Copilot grounding. The controls solve different parts of the trust problem.
Unit 42 recovered a live threat actor’s autonomous attack loop: DeepSeek and Hermes Agent selected targets, sourced exploits, and launched attempts before an agent error exposed the operation.
Coordinated research shows Microsoft Copilot for Word copying hidden prompt injection into downstream documents. The lab chain is reproducible, but propagation still requires Copilot-assisted reuse.
IBM’s 602-organization breach study links AI-enabled attacks to $6 million average costs, while access controls, connected applications, cloud configuration, and machine identities remain the actionable failures.
UK AISI and NIST CAISI found Kimi K3 below leading frontier models in preliminary cyber tests, yet it completed a 32-step attack range once in ten attempts and did not refuse offensive tasks.
Five newly published CVEs affect the official MCP Ruby SDK through 0.22.0. Version 0.23.0 adds DNS-rebinding defenses and resource limits, but deployers must configure session ownership validation.
Proofpoint observed underground sellers advertising indirect prompt-injection generators for email, PDFs, calendar invites, and webpages. The activity is experimental, but it turns agent input channels into a concrete defensive priority.
CVE-2026-47427 crashes GitHub MCP Server versions before 1.1.0 with a malformed completion request. The patch is clear; the remote threat model needs nuance.
HashiCorp disclosed three Terraform MCP Server flaws spanning unauthenticated bearer-token theft, stateful session takeover, and stateless cross-tenant credential reuse. Version 1.1.0 fixes all three.
Netskope telemetry shows remote MCP transactions rising 375% in ten weeks while weekly downstream AI data-policy violations increased from 12 to 31 over a year. The report makes output authorization a first-class agent control.
Ruflo before 3.16.3 exposed an unauthenticated MCP bridge in its default Docker stack. The fix closes the shell path, but operators must investigate keys, MongoDB, and AgentDB memory.
Microsoft’s Project Perception coordinates red, blue, and green security agents, while MAI-Cyber-1-Flash routes most MDASH work to a specialist model. The design is notable; its launch benchmarks need careful reading.
n8n published 16 security advisories spanning host command execution, credential theft, MCP SSRF, file access, SQL injection, and cross-user isolation. Version 2.32.1 is the safest common remediation floor.