Fetching from the wire…
Top 5 · 2026-02-20 · source-backed
A critical code injection vulnerability was disclosed in Microsoft's Semantic Kernel Python SDK — the flagship SDK underpinning their agent framework strategy. The InMemoryVectorStore filter allows authenticated attackers with low privileges to execute arbitrary code with no user interaction. Patched in python-1.39.4. This follows the LangChain SSRF CVE from last week, confirming AI framework supply chain security is a recurring critical vulnerability category. What to do: If you're using Semantic Kernel, update to python-1.39.4 immediately. Avoid InMemoryVectorStore in production environments.
Each link below shares sources, entities, or timing with this story.
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
Unsanitized shell command execution in Microsoft's Agent Framework — days from GA — allows prompt injection to escalate to arbitrary OS command execution. The flaw passes user-controlled or model-generated inputs directly through the shell without sanitization. If you're migra...
XBOW — a fully autonomous AI pentesting agent that has ranked at or near the top of HackerOne's leaderboard for over a year — is publicly credited with finding CVE-2026-21536, a CVSS 9.8 RCE in Microsoft's Devices Pricing Program cloud service. First time an autonomous agent g...
Bitdefender published the most alarming MCP security metric to date: 53% of open-source MCP server implementations rely on insecure static credentials while only 8.5% use OAuth. The report identifies five risk categories: opt-in (not default) security, supply chain poisoning,...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.