Overview On September 11, 2026, the Huntress SOC released a set of cases tracked over a nine-month period. The conclusion ran counter to their own expectations: what is currently being exploited more frequently in the AI domain is not the models or the AI companies themselves, but rather the everyday...
Tag: LLM
AI Security Incident Case: Amazon Kiro Prompt Injection Vulnerability Analysis
Overview On August 27, 2026, cybersecurity research firm Mindgard publicly disclosed a prompt injection vulnerability in Amazon Kiro IDE. Kiro is an AI-driven development environment launched by Amazon, equipped with an agent capable of reading/writing repository files, invoking native tools, and triggering IDE features. Discovered and reported on December 11,...
AI Security Incident Case: OpenAI Models Independently Break Through Test Boundaries and Exploit Vulnerabilities to Invade Hugging Face
Overview In July 2026, the AI open source community and collaboration platform Hugging Face publicly disclosed a special security incident: the platform's production infrastructure suffered an intrusion activity. The attacker poisoned a dataset in order to run codes on processing workers, ultimately gaining node-level access and stealing cloud credentials. It...
AI Security Incident Case: Ghostcommit Attack Leveraged Images to Steal Secrets
Overview On July 11, 2026, two researchers from the ASSET Research Group at the University of Missouri-Kansas City, Sudipta Chattopadhyay and Murali Ediga, disclosed a novel attack technique named Ghostcommit. This attack is capable of exfiltrating the entire contents of a target's .env file. The ingenuity of this attack lies...
RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes
Company Profile ZeroPath is an AI-native application security startup founded in 2024, and its core products also use the eponymous brand ZeroPath. The company focuses on using AI to automatically discover, verify and fix code vulnerabilities, trying to break through the limitations of traditional SAST, SCA, Secrets scanning and IaC...
OpenClaw Security Issues: Add a “Security Guardrail” to Your AI Application
In 2026, AI intelligent agent technology will usher in a full-scale explosion. As a representative project, OpenClaw (formerly known as Clawdbot and Moltbot) is highly favored for its powerful capabilities-it can integrate multi-channel communication capabilities with large language models to build customized AI assistants with persistent memory and active execution...



