LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

zeroday.news ·

A new report indicates that a significant majority of AI tools within enterprise environments operate without IT oversight, contributing to an increasingly risky AI agent ecosystem. The study, conducted by AI security vendor Reco, analyzed anonymized platform telemetry from large enterprises, publicly available Model Context Protocol (MCP) servers, and vulnerability disclosures from the National Vulnerability Database.

The report, titled "The State of Agent Security 2026," found that 80% of AI tools lack IT governance. In small and medium-sized businesses (SMBs), the research estimated an average of 414 unsanctioned AI tools per 1000 employees. Reco's CEO, Ofer Klein, noted that while AI agents are now integrated into daily business workflows, only 20% of these tools in enterprise ecosystems are currently managed by IT, exposing organizations to new operational risks. He explained that agents embedded in applications can leverage existing permissions, OAuth grants, and workflow access, potentially creating "toxic combinations" that expose data and trigger unauthorized actions.

A particularly concerning finding from Reco's analysis of 500 MCP servers, which facilitate connections between AI agents and data or actions, revealed that half of these servers can directly execute shell commands. This capability could allow a prompt-injection attack to escalate to operating system access. Furthermore, over 80% of these servers can read or write local files, and approximately 75% can make outbound network calls. The report highlighted that these tools are often loaded by agents in large numbers, frequently through marketplaces without a review process. Only about a quarter of these tools expose a network endpoint rather than running locally, and half of those lack any authentication, creating remotely accessible tools with host-level reach and no security measures.

The study also found that nearly two-thirds (62%) of AI agents combine command execution, file access, and network egress capabilities in a single package. Reco warned that this combination provides an end-to-end toolkit for attackers to "find data, act on it, and move it off the machine."

In addition to oversight issues, the report tracked 637 vulnerabilities across AI agents and large language model (LLM) tools. Of these, 525 were disclosed within the last 18 months, including at least 111 critical vulnerabilities with CVSS scores of 9.0 or higher. The average monthly disclosure rate for these vulnerabilities has increased significantly, rising from fewer than five per month during 2023 and 2024 to approximately 29 per month since January 2025. Reco cautioned that vulnerabilities are being published at a pace that outstrips organizations' ability to implement patches.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]

CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

security

Election official says Tina Peters would be consultant, won’t have access to election systems

Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction. The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.

security

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries