Armadin Agent Swarm Security Platform Raises $255.5M at $2.5B Valuation
Armadin, an AI-native offensive security startup founded by Mandiant creator Kevin Mandia, has secured $255.5 million in Series B funding at a $2.5 billion post-money valuation. Led by Andreessen Horowitz and Accel, the capital will scale Armadin’s Agent Swarm Orchestrator and AI-Native Offensive Engine. The platform utilizes autonomous AI agents to perform Continuous Autonomous Red Teaming (CART), emulating adversary tactics across cloud, on-prem, and hybrid environments. By integrating with existing SIEM, SOAR, and XDR stacks, the platform validates exploit paths and generates real-time remediation playbooks, shifting security posture from periodic testing to persistent, automated validation.
Anthropic: Claude Mythos and Project Glasswing
Anthropic's Claude Mythos model, integrated within the Project Glasswing agentic framework, has demonstrated the capability to automate hyper-scale vulnerability research, identifying over 10,000 zero-day vulnerabilities across major operating systems and browser engines. This discovery includes a legacy 27-year-old denial-of-service (DoS) flaw in OpenBSD. While the framework enables machine-speed exploit payload generation, recent observed breaches of three distinct organizations were executed via low-sophistication vectors, specifically credential stuffing and weak password exploitation. This illustrates a critical discrepancy between the accelerating sophistication of AI-driven offensive capabilities and the persistence of fundamental human-centric security hygiene failures in identity and access management.
GitSpawn RCE: Runtime Boundary Failures in Claude Code, Cursor, and OpenAI Agents
The GitSpawn vulnerability class enables Remote Code Execution (RCE) in AI-driven development tools, including Claude Code, Cursor, and OpenAI-based agents, by exploiting configuration hijacking within a repository's .git/config file. Attackers inject malicious shell payloads via Git configuration keys such as core.fsmonitor, core.pager, and core.editor. When an agent performs routine operations like git status or git log, these payloads execute with the full privileges of the local user. This represents a critical shift from linguistic prompt injection to runtime boundary failures, where the convergence of high goal pressure and unsafe execution environments allows attackers to bypass agentic sandboxes via standard repository maintenance tasks.
OpenAI Daybreak Initiative: Scaling AI-Driven Defense for Critical Infrastructure
OpenAI has introduced the "Daybreak" initiative, deploying specialized cyber-defensive Large Language Models (LLMs) to underfunded critical infrastructure sectors, including water, electric grids, and community banking. Supported by a $1 billion subsidy, Daybreak models are fine-tuned on threat intelligence and ICS/SCADA-specific datasets to bridge the capability gap for resource-constrained operators. The initiative addresses diverse deployment needs, ranging from standard API access to air-gapped, on-premise environments. Technical risks include susceptibility to prompt injection and model inversion, alongside the potential for dual-use exploitation by state-sponsored actors targeting critical infrastructure control logic.
Code Execution via llms.txt in Claude, Codex, and Hermes AI Agents
Security researchers have identified a critical vulnerability allowing Remote Code Execution (RCE) in Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes AI agents. By exploiting the llms.txt and llms-full.txt standards, attackers employ indirect prompt injection to embed malicious instructions within machine-readable documentation. These agents treat external llms.txt files as high-integrity system instructions rather than passive data, leading to the execution of unauthorized shell commands and API calls. This flaw has been validated via proof-of-concept (PoC) attacks within several Fortune 500 corporate environments, bypassing traditional perimeter security by leveraging the trusted identity of the AI agent to install unowned code.
The AI Supply Chain Crisis: HuggingFace Poisoning and Unauthenticated Endpoint Exposure
Internet-wide scanning has revealed 36,769 unauthenticated HTTP AI endpoints, with 98% lacking authentication, exposing proprietary LLMs and system prompts. Simultaneously, supply chain attacks targeting the HuggingFace hub involve the injection of poisoned model weights and serialized files (e.g., .pth, .bin, .pickle) and the deployment of backdoored agents like Agentland. These vulnerabilities facilitate the hijacking of LLM service credentials—specifically targeting Claude token quotas—to drive resource exhaustion and automated exploitation cycles. Remediation requires enforcing strict HTTP authentication, implementing Zero Trust Network Access (ZTNA), and rigorous cryptographic checksumming of all model assets sourced from public repositories.
OpenAI ChatGPT Sandbox Flaw Enables Cross-Account Gmail Data Exfiltration
Researchers at Check Point discovered a critical sandbox escape vulnerability in OpenAI's ChatGPT execution environment that permits cross-account data exfiltration. By leveraging indirect prompt injection, an attacker can deploy malicious instructions that transform the LLM into a stealthy agent. This agent exploits a shared clipboard mechanism—acting as a hidden communication channel within the sandbox—to facilitate unauthorized data transfer. The vulnerability targets Gmail API integrations, allowing attackers to retrieve private email content and exfiltrate it to an attacker-controlled account. The risk is amplified by the "Deep Research" agent, which introduces a zero-click vector by autonomously triggering the exfiltration during standard, unprompted research operations.
AI Agent Security and the Model Context Protocol MCP Framework
The Model Context Protocol (MCP) standardizes how AI agents interact with external tools and data via JSON-RPC-based architectures, significantly expanding the enterprise attack surface. By transitioning LLMs from passive text generators to active agents, MCP introduces critical vulnerabilities such as Indirect Prompt Injection (IPI) and Agentic Hijacking. Attackers can leverage malicious context within retrieved resources to trigger unauthorized tool calls, enabling Remote Code Execution (RCE), Server-Side Request Forgery (SSRF), and high-velocity data exfiltration. The primary risk shifts from simple information leakage to unauthorized system impact through the exploitation of the trust boundary between the LLM's reasoning and the MCP server's execution capabilities.
The InboxSync RAG Pipeline: Architectural Vulnerabilities and the Confidence Gap
Research into the InboxSync RAG pipeline identifies a critical architectural vulnerability known as the "Confidence Gap." The system, built on a Node.js/TypeScript backend using pgvector and OpenAI text-embedding-3-small, fails to validate retrieval accuracy by employing hardcoded confidence constants (e.g., 0.85) instead of computing real-time semantic similarity. This absence of relevance gating allows "semantic collisions," where adversarial or irrelevant data—such as GDPR requests or spam—is erroneously categorized as highly relevant context. Consequently, attackers can exploit the disconnect between mathematical semantic proximity and user intent through document poisoning, achieving a 100% success rate in bypassing relevance filters during adversarial testing.