Zenity Labs has documented attackers exploiting unpatched LiteLLM vulnerabilities and unauthenticated Ollama endpoints to run autonomous pentesting campaigns, steal compute, and exfiltrate data from victim organisations.
The latest AI security developments, threats, and industry updates.
Zenity Labs has documented attackers exploiting unpatched LiteLLM vulnerabilities and unauthenticated Ollama endpoints to run autonomous pentesting campaigns, steal compute, and exfiltrate data from victim organisations.
A Censys scan found 12,520 publicly exposed MCP services — 40% with no authentication at all. Combined with 106 zero-days found in an automated academic scan and a CVSS 10.0 flaw in a popular MCP server, the AI agent infrastructure layer is becoming one of 2026's most under-patched attack surfaces.
Mozilla's Zero Day Investigative Network published research showing that Claude Code, Cursor, GitHub Copilot, and Gemini CLI can all be manipulated into executing attacker-controlled payloads delivered via DNS TXT records from seemingly clean GitHub repositories.
A solo researcher has documented 9,330 malicious GitHub repositories designed to poison AI coding agent sessions and deliver credential-stealing malware via blockchain-hosted C2 infrastructure.
Georgia Tech's Vibe Security Radar tracked 35 CVEs in March 2026 alone attributable to AI-generated code, more than all of 2025 combined. The Cloud Security Alliance's research series documents credential sprawl, governance gaps, and a structural security debt building inside the open-source ecosystem.