Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
llm-openrouter 0.7 Adds Server-Side Shell and WebFetch Tools — Securing LLM Agent Tool Execution Against Prompt Injection
Introduction On August 21, 2026, Simon Willison released llm-openrouter 0.7, an update to the OpenRouter plugin for his widely used llm CLI ...
CUSTODY Framework: Constraining Agentic AI on Enterprise Networks — Detection and Containment Guide for Defenders
Introduction When Jake Williams — former NSA hacker, SANS instructor, and one of the more credible voices in applied defense — decides to re...
AI Agent 'Mind Viruses': Detecting and Containing Self-Propagating Prompt Injection in Agent Harnesses
Introduction On August 10, 2026, security researchers at Anthropic and Switzerland's EPFL released a preprint demonstrating something many o...
CVE-2026-75110: MemOS AI Agent Authentication Bypass (CVSS 9.8) — Detection and Remediation Guide
CVE-2026-75110: When "Authentication Enabled" Still Means Wide Open NVD has published CVE-2026-75110, a CVSS 9.8 (Critical) vulnerability in...
MCP Servers Are Leaking Enterprise Secrets: Detection and Hardening Guide for AI Agent Deployments
The Quiet Credential Leak in Your AI Stack The Model Context Protocol (MCP) has become the de facto standard for connecting AI agents to ent...
Cyera's $1B Oasis Security Acquisition: What AI Agent Identity Convergence Means for Defenders in 2026
Introduction Cyera's roughly $1 billion acquisition of Oasis Security, reported by Dark Reading, is more than another consolidation headline...
PraisonAI praisonaiagents 1.6.77 Unauthenticated Remote Code Execution — Detection and Remediation Guide
Introduction Security Arsenal is issuing this advisory following the public release of exploit code for an unauthenticated remote code execu...
GhostJacking: Defending AI Agents Against Alert-Based Manipulation — Detection and Identity Governance Hardening Guide
Introduction Security researchers have disclosed a new attack technique dubbed GhostJacking that turns an organization's own security teleme...
Prompt Injection Defense: Why Transparent AI Agents Are the Detection Layer Your SOC Is Missing
Introduction A recent opinion piece on CyberScoop makes an argument that every security leader deploying AI agents needs to internalize: the...