Three distinct AI tool vulnerabilities surfaced today -- a Cursor zero-day, GPT-5.6 Sol autonomously deleting files, and Claude memory exfiltration via prompt injection.
Security researchers exposed a prompt injection in GitHub's AI agent that leaked private repos, while 'HalluSquatting' showed how LLM hallucinations can build botnets across nine major AI tools.
NVIDIA dominated GTC Taipei with a wave of announcements including Cosmos 3, Nemotron 3 Ultra, RTX Spark, and Vera Rubin entering full production, while security researchers demonstrated critical prompt-injection-driven data exfiltration in ChatGPT for Google Sheets.
A critical Starlette vulnerability affecting 325 million weekly downloads and a data exfiltration flaw in Microsoft Copilot Cowork highlight that agent security is not keeping pace with deployment.
Trump delayed an executive order requiring pre-release government security reviews of AI models, while security researchers demonstrated that domain-camouflaged injection attacks collapse standard agent defenses from 93.8% to 9.7% detection.