New research and reporting highlight how indirect prompt injection and agent memory can create persistent insider-style risk, while coding agents remain susceptible to prompt-driven unsafe actions. Adjacent cybersecurity updates, including CISA KEV additions and critical flaws in self-hosted platforms, reinforce that classic exploitation paths still underpin most AI compromise scenarios.
KEV
AI Security Daily Briefing — December 17, 2025
NVIDIA patches a critical remote-code flaw in Isaac Lab, CISA adds a Fortinet signature verification vulnerability to the KEV catalog amid exploitation, and Anthropic finds that just 250 malicious documents can poison LLM training.
AI Security Daily Briefing — October 22, 2025
In the last 24 hours: Oracle’s October CPU ships 374 fixes (many unauth RCEs); Pwn2Own Ireland logs 34 new zero-days on Day 1; CISA flags Windows SMB Client and Kentico bugs as exploited; and a high-severity Rust async-tar flaw (“TARmageddon”) emerges. Plus, the U.N. readies a global cybercrime pact for signature.