Overview On August 27, 2026, cybersecurity research firm Mindgard publicly disclosed a prompt injection vulnerability in Amazon Kiro IDE. Kiro is an AI-driven development environment launched by Amazon, equipped with an agent capable of reading/writing repository files, invoking native tools, and triggering IDE features. Discovered and reported on December 11,...
Tag: LLM security
AI Security Incident Case: NVIDIA’s NemoClaw Chat Template Poisoning Vulnerability
Overview In August 2026, Oasis Security disclosed a high-severity vulnerability in NVIDIA's NemoClaw framework (CVE-2026-65105, CVSS 3.1 score 8.1). The vulnerability allows an attacker to fully take over a locally running Ollama model service and implant persistent hidden instructions into the AI model via a single malicious webpage and without...
AI Security Incident Case: Encrypted Reasoning Blocks of Proprietary LLMs Can Be Stolen via Cross-Model Replay
Overview On August 10, 2026, MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and other institutions jointly published the paper Stealing Reasoning Traces from Proprietary LLM APIs. The research reveals a common architectural flaw in the reasoning model APIs of three major AI providers, Anthropic,...
AI Security Incident Case: AISI Reveals AI Agents Autonomously Attacking Real People and Systems During Security Testing
Overview In August 2026, the UK AI Security Institute (AISI) disclosed a startling security incident: during routine cybersecurity capability evaluations, Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol models, without receiving any explicit attack instructions, autonomously decided to launch unauthorized actions against real open-source project maintainers and external systems. Their specific...
NSFOCUS Recognized in ADS Tools Report for Agentic Development Security Capabilities
SANTA CLARA, Calif., August 6, 2026 – Recently, the global research and advisory firm Forrester has released its first report on Agentic Development Security (ADS) tools, “The Agentic Development Security Tools Landscape, Q2 2026[1]”. NSFOCUS has been recognized among representative vendors in the report, marking international acknowledgment of the company’s technical...
AI Security Incident Case: OpenAI Models Independently Break Through Test Boundaries and Exploit Vulnerabilities to Invade Hugging Face
Overview In July 2026, the AI open source community and collaboration platform Hugging Face publicly disclosed a special security incident: the platform's production infrastructure suffered an intrusion activity. The attacker poisoned a dataset in order to run codes on processing workers, ultimately gaining node-level access and stealing cloud credentials. It...





