What just shiftedLOG-15 · 2026-07-20
Mandiant M-Trends 2026: Dwell Time Collapses to 22 Seconds, Forcing Runtime AI Security Shift
Mandiant M-Trends 2026 reports the median time from initial access to threat handoff collapsed from over 8 hours in 2022 to just 22 seconds in 2025. CSA 2026 State of Modern Application and AI Security survey of 900+ cybersecurity leaders finds organizations struggling to distinguish exploitable vulnerabilities from theoretical findings while investment priorities shift toward runtime security, continuous monitoring, and production defense. AI-powered applications increase the need for real-time visibility as the patch gap leaves organizations exposed when AI accelerates both vulnerability discovery and exploit generation.
Sharpens: Security operations function leads must prioritize real-time AI observability and runtime monitoring over purely pre-production controls. Implement continuous AI model I/O logging for forensic readiness. Develop AI-specific incident response playbooks that account for sub-minute dwell times. Invest in automated runtime exploit mitigation capabilities and endpoint instrumentation that monitors AI assistant emissions regardless of sanctioned domain. · source
New way to build itMDS-02 · 2026-07-20
Unit 42 Exposes MCP Sampling Attack Vectors: Resource Theft, Hijacking, Covert Tool Calls
Palo Alto Unit 42 demonstrated that the Model Context Protocol (MCP) sampling feature reverses the client-server interaction pattern, allowing MCP servers to proactively request LLM completions and enabling three critical attack vectors. Resource theft drains AI compute quotas for unauthorized workloads. Conversation hijacking injects persistent instructions to manipulate responses and exfiltrate data. Covert tool invocation performs hidden file system operations without user awareness. The DoD released MCP security design guidance in June 2026. The 2026 MCP Security Top 10 ranks unauthenticated access and confused deputy attacks as highest risks.
Sharpens: Application security function leads must audit all MCP server integrations for sampling capability exposure and enforce explicit user confirmation for server-initiated LLM requests. Implement tool invocation logging with user-visible indicators and scan MCP server manifests and tool definitions during the secure SDLC. Treat MCP servers as untrusted external services requiring least-privilege access and network segmentation. · source
New way to build itDSP-21 · 2026-07-20
Microsoft EchoLeak: Zero-Click RAG Poisoning Exfiltrates Corporate Data via Copilot
Microsoft EchoLeak vulnerability demonstrated that a single malicious email can manipulate Microsoft 365 Copilot into retrieving and exfiltrating sensitive corporate data through rendered image requests without the user ever opening the message. The RAG poisoning attack chain spans five stages: planting hidden instructions in shared documents via invisible text and white-on-white formatting, triggering retrieval through routine employee queries, executing attacker-controlled directives that override system prompts, collecting data within the retrieval scope including emails and CRM records, and exfiltrating over trusted SaaS channels through markdown image rendering that blends into normal application traffic.
Sharpens: Data security function leads must implement content sanitization pipelines that strip invisible Unicode, ANSI escape sequences, and white-on-white text before RAG ingestion. Restrict markdown image rendering to explicitly trusted domains. Apply least-privilege retrieval scoping tied to requesting user access. Schedule regular red-team assessments against RAG knowledge bases treating every connector, document type, and tool integration as an attack surface. · source
New way to build itMDS-07 · 2026-07-20
Reasoning Models Autonomously Jailbreak Other AI at 97% Success Rate
A 2026 Nature Communications study found that large reasoning models can autonomously jailbreak other AI systems with a 97% success rate. Group-IB reports dark web jailbreak commerce surged 371% since 2019, with frameworks like BRUTUS sold as SaaS subscriptions ($50-200 per month). DarkLLMs such as NytheonAI, Xantrox, and EvilGPT offer jailbroken chatbots for malware writing and phishing. State-backed APT groups including APT28 (LameHug AI infostealer) and APT35 (GenAI-generated malicious PDFs) are now integrating jailbreak techniques into attack chains. Static detection rules cannot keep pace with iterating frameworks that release new bypass methods within weeks.
Sharpens: Security function leads must mandate continuous AI red teaming against autonomous jailbreaking, integrate dark web threat intelligence into detection rule pipelines, and implement layered jailbreak detection covering input filtering, output moderation, and behavioral monitoring. Scope testing against OWASP LLM Top 10 and MITRE ATLAS categories per deployment use case. · source
On the frontiernot yet on the CSA spine · 2026-07-19
Dual-Channel Agent Governance Gap Exposed by EchoLeak and ForcedLeak Attacks
The Aurascape 2026 landscape analysis identifies a structural blind spot in AI security: dual-channel agent control. Most security platforms inspect either the model conversation channel (prompts and responses) or the tool-execution channel (API calls and system actions), but not both simultaneously with correlated data lineage. The EchoLeak attack (CVE-2025-32711) exploited this gap against Microsoft 365 Copilot via zero-click indirect prompt injection, while ForcedLeak (CVSS 9.4) used a $5 domain re-registration to exfiltrate data through Salesforce Agentforce. Neither attack would have been caught by single-channel inspection.
Sharpens: Evaluate whether your AI security tooling provides cross-call data lineage that correlates model-level prompts with tool-level actions. When procuring agentic AI security tools, require dual-channel inspection capabilities as a non-negotiable evaluation criterion. For existing agent deployments, implement compensating controls: session-level audit logging that links prompt history to tool-call sequences, and blast-radius containment that limits what any single agent can access regardless of prompt content. · source
What just shiftedMDS-06 · 2026-07-19
Only 26 Percent of Organizations Conduct Proactive AI Security Testing Amid 97 Percent Jailbreak Success Rates
Mindgard's May 2026 benchmarks reveal a stark preparedness gap: only 26 percent of organizations conduct proactive security testing specific to AI systems, while multi-turn jailbreaks achieve a 97 percent success rate within five conversational turns. Single-shot red teaming is insufficient because risks compound across conversational turns. Organizations practicing continuous and structured AI red teaming experience significantly fewer security incidents and vulnerabilities. Budget and workforce skills gaps remain the top inhibitors preventing organizations from operationalizing AI red teaming.
Sharpens: Shift from periodic manual red teaming to continuous automated adversarial testing against all production AI models. Implement multi-turn testing scenarios as standard practice, not just single-shot prompts. Establish a weekly red teaming cadence integrated into your CI/CD pipeline for AI systems. Track and report jailbreak success rates over time as a core AI security KPI for your board and risk committee. · source
Control ids above refer to the CSA AI Controls Matrix (AICM).