JadePuffer exploits a CVE-2025-3248 vulnerability in Langflow to automatically encrypt AI model weights and training data with EncForge, causing estimated damages of $75,000 to $500,000 per model.
A missing prompt injection protection measure in the Azure DevOps MCP server allows hidden comments to redirect control flow of AI agents and trigger data leaks.
Nearly 7,600 malicious GitHub repositories lure developers and AI systems with fake AI integration tools and MCP servers to install SmartLoader malware.