vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and requires user interaction to exploit. The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
threat-intel How MCP Servers Can Expose Enterprise Secrets The Model Context Protocol (MCP), a new standard allowing AI agents to access enterprise systems and data, introduces significant security risks due to the way it handles secrets. MCP servers routinely store credentials… The Hacker News · Aug 17, 2026 High CVE-2025-6514aisecretsmcp
vulnerability 2-Click Cursor Exploit Enables Dev Environment Takeover A vulnerability in Cursor AI, an AI coding tool used by over 50,000 enterprises including 64% of the Fortune 500, allows attackers to install malicious code through a cleverly disguised pull request link. Researchers at… Dark Reading · Jul 15, 2026 High aisecuritypull request
threat-intel Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) A SANS Internet Storm Center analysis reveals a widespread scanning campaign targeting servers to identify and exploit vulnerabilities related to AI assistants and local Large Language Models (LLMs). The scans are active… SANS Internet Storm Center · Jul 13, 2026 High aillmscanning
threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of M… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials
threat-intel Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A critical vulnerability was discovered in Amazon Q Developer, allowing attackers to execute arbitrary code and steal developer credentials by leveraging Model Context Protocol (MCP) configurations within a cloned reposi… The Hacker News · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958CVE-2025-59536mcpcloud securitydeveloper credentials
threat-intel AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing age… The Hacker News · Jun 19, 2026 High CVE-2026-26030CVE-2026-25592remote code executionai agentlocalhost
threat-intel Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code A new attack method, dubbed ‘Agentjacking,’ is exploiting vulnerabilities in AI coding agents like Claude Code and Cursor by tricking them into executing malicious code through crafted error reports sent via Sentry. This… The Hacker News · Jun 12, 2026 High aiagentjackingsentry