Gong and other scholars have been issuing warnings about the security vulnerabilities of AI agents for a while. They publish ...
CVE-2026-5426, a hardcoded ASP.NET machineKey in KnowledgeDeliver, was exploited as a zero-day in ViewState deserialization ...