Fetching from the wire…
Security2026-08-09 · source-backed
LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, presented at Black Hat (The Register). Insecure deserialization, SSRF, path traversal, use-after-free. That's the point: prompt-controlled content crosses into trusted framework logic, and then it's just ordinary appsec. A Microsoft Agent Framework checkpoint-deserialization flaw let one user plant a payload via prompt injection that fired when a different user reloaded their session ($10,000 bounty). Google ADK shipped an unauthenticated HTTP API, on by default, that executed arbitrary Python and exposed service-account credentials ($3,133.70). Your agent framework is a web application. Scan it like one.
Each link below shares sources, entities, or timing with this story.
Unified governance across LangGraph, CrewAI, AutoGen, Google ADK, AWS AgentCore, Microsoft Foundry, and Salesforce Agentforce. Evaluation studio for pre-production behavior testing. Addresses "AI sprawl" with cross-framework observability. Source
Diagrid shipped July 28, bringing durable execution plus cryptographic history signing, execution lineage propagation, and workflow attestation from Dapr 1.18 into LangGraph, Microsoft Agent Framework, Google ADK, AWS Strands, OpenAI Agents SDK, Claude Managed Agents, CrewAI,...
github.com/luckyPipewrench/pipelock — All-in-one security harness with 9-layer scanner pipeline: DLP, SSRF, bidirectional MCP scanning, tool poisoning detection. Zero code changes — agents use it as system proxy. Works with Claude Code, Cursor, CrewAI, LangGraph, AutoGen.
A Rust binary that replaces LangChain, CrewAI, and AutoGen with zero dependencies. 222 HN points and 122 comments signal strong developer resonance with framework fatigue. GitHub ---
Julie Brunias presented the Synthetic Agent Deception Framework at DEF CON 34's AI Village: 5,119 evaluation rows, eight architectures, 32 payloads. Keeping Claude Sonnet fixed and swapping only the wrapper moved Agent Compromise Rate from 11.9% (CrewAI) to 31.1% (SmolAgents),...
Both predecessors enter maintenance-only mode. The unified framework adds graph-based multi-agent orchestration, session state management, type-safe middleware, telemetry, and interoperability with A2A, AG-UI, and MCP protocols. Available in .NET and Python. Source
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.