AI in the Build Pipeline: How Software Supply Chain Security Must Evolve
Software supply chain security was already complex, but the integration of AI into the build pipeline has introduced new risks that traditional…
Software supply chain security was already complex, but the integration of AI into the build pipeline has introduced new risks that traditional…
A webinar hosted by OX researchers on July 22, 2026, covering AI integration's impact on attack surface, MCP server findings, and supply…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
Copilot Studio allows building custom AI agents that can reach into business systems, increasing the attack surface for poisoned tool descriptions.
Azure AI Foundry enables creation of AI agents that run multi-step jobs, which can be exploited via MCP tool description poisoning.
A high-severity flaw in Amazon Q Developer could allow a malicious repository to execute commands and steal a developer's cloud credentials. The…
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
A vulnerability in Windsurf allowed attacker-controlled content to rewrite local MCP config and register a malicious server, leading to command execution.
A flaw in Amazon Q Developer could let malicious repositories run code through MCP configurations.
Sentry, an open-source error-tracking and performance-monitoring platform, was exploited in the Agentjacking attack due to its event ingestion and MCP server.