π¨ ACTIVE EXPLOITS & INCIDENTS
- Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints β The Hacker News Threat actors actively exploit CVE-2026-33017 (CVSS 9.3), an unauthenticated remote code execution vulnerability in Langflow AI app endpoints, to deploy Monero cryptocurrency miners. Scanning and attacks targeting exposed AI infrastructure continue in the wild.
- Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses β The Hacker News McAfee Labs uncovered an ongoing campaign distributing unsigned browser extensions that stealthily replace cryptocurrency wallet addresses during transactions, stealing funds. Variants are delivered via .NET and Golang unsigned installers, indicating active targeting of crypto users.
- Critical flaw in SimpleHelp exploited in attacks targeting sensitive credentials β Cybersecurity Dive Two previously unknown malware samples are actively used to steal AI assistant tokens and sensitive credentials via a critical SimpleHelp vulnerability. This indicates ongoing targeted attacks against remote support infrastructure.
π VULNERABILITIES & CVEs
- GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks β The Hacker News New research reveals a bypass called GuardFall that circumvents safety checks in 10 of 11 popular open-source AI coding agents, exploiting decades-old shell injection techniques. This exposes AI development workflows to remote code execution risks, demanding urgent review of AI agent security controls.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS β The Hacker News QiAnXin XLab tracks RustDuck, a fast-evolving two-stage botnet targeting home routers, IP cameras, Android boxes, and unsecured servers. Written in Rust, it rapidly adapts to build a large DDoS network, highlighting the growing threat to IoT and edge devices.
- Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data β The Hacker News / Microsoft Security Blog Microsoft Incident Response research demonstrates how attackers can poison AI agent tool descriptions (MCP tools) to exfiltrate sensitive company data without triggering alarms. This subtle manipulation turns trusted AI agents into covert data loss vectors, emphasizing the need for enhanced AI agent monitoring and validation.
π VENDOR BULLETINS & ADVISORIES
- Securing AI agents: When AI tools move from reading to acting β Microsoft Security Blog Microsoft details mitigation strategies against MCP tool poisoning attacks that hijack AI agents to perform unauthorized actions. Guidance includes detection, containment, and prevention best practices for organizations deploying AI automation.
- Whatβs new in Microsoft Security: June 2026 β Microsoft Security Blog June updates focus on strengthening identity and multicloud security foundations, data protection, and securing AI developer workflows. Key improvements target AI innovation environments and cloud-native security controls.
- Accelerating the quantum-safe timeline β Microsoft Security Blog Microsoft announces accelerated efforts for quantum-safe cryptography readiness, urging organizations to begin early transitions to post-quantum algorithms to mitigate emerging quantum computing threats.
π° LESSER-KNOWN / UNDER-REPORTED
- Fake Perplexity extension on Chrome Web Store tracked searches β BleepingComputer A malicious Chrome extension impersonating the Perplexity AI answer engine was found intercepting user search traffic and collecting browsing data. Users should audit installed extensions and remove suspicious AI-related plugins.