Threat Feed

NHI & AI-agent security, as it’s disclosed.

Publicly disclosed non-human-identity, AI-agent, MCP, and cloud-identity security incidents and advisories. Sourced from authoritative publishers (CISA KEV, NVD/CVE, vendor PSIRTs, named researchers). Every item links to its original source; our analysis is shown separately. The feed is intentionally sparse when there is nothing real to report.

01 · Advisories · 3 sourced items

Every item carries a real, dated, linked source.

The no-fabrication law as code: an unsourced or undated item cannot ship — the build fails. We never wholesale-republish link-only sources; we summarise and link to the original.

high2026-06-24Model Context Protocol (specification)Public domain

MCP tool calls are a new identity supply chain — and a new attack surface

A TrustFix explainer on the security risks introduced when AI agents call tools over the Model Context Protocol — tool poisoning, tool-description injection, indirect prompt injection, and unmediated delegation — and what is provable about each.

Agent: tool poisoningAgent: tool-description injectionAgent: indirect prompt injectionAgent: over-privileged agentAgent: unmediated delegation hop
info2026-06-24OWASP FoundationPublic domain

The OWASP Non-Human Identity Top 10: a shared language for NHI risk

A TrustFix explainer on the OWASP Non-Human Identity Top 10 — the emerging shared vocabulary for the risks that service accounts, tokens, and AI agents introduce. We map each category to what is provable versus assumed.

NHI1 Improper OffboardingNHI2 Secret LeakageNHI5 Overprivileged NHINHI7 Long-Lived SecretsNHI10 Human Use of NHI
In the newsTHREAT FEED

Every breach here was a non-human identity.

Not phished passwords — leaked tokens, forgotten OAuth apps, unrotated service accounts, stolen signing certs. The machine identities nobody was watching. Real, public incidents; click any to read the source.

IN FOCUSMay 2026· CISA / DHS (via Nightwing contractor)
CISA contractor leaked AWS GovCloud admin keys in a public GitHub repo for ~6 months
Administrative credentials for three AWS GovClouRead the source
May 2026Extended-Validation code
DigiCert social-engineered into issuing EV code-signing certs later used to sign malware
DigiCert and EV code-signing subscribers (incl. Lenovo, Kingston, Shuttle, Palit)
Apr 2026MCP servers — the creden
Model Context Protocol design flaw exposes thousands of MCP servers to remote code execution
The AI-agent ecosystem (7,000+ publicly reachable MCP servers; ~200k vulnerable instances)
Apr 2026A Google Workspace OAuth
Vercel breached via an "Allow All" OAuth grant to a compromised third-party AI tool
Vercel and a subset of its customers
Feb 2026Stolen system/service cr
AI-assisted attacker breaches nine Mexican government agencies, exfiltrating taxpayer records
Mexican federal, state and municipal agencies including the tax authority (SAT)
Nov 2025Stolen npm publish token
Shai-Hulud 2.0: self-replicating npm worm compromises ~500 packages, leaks secrets across 25k+ repos
npm ecosystem incl. packages from Zapier, PostHog, Postman, AsyncAPI, ENS
Nov 2025OAuth access and refresh
Gainsight Salesforce OAuth integration abused to access data at hundreds of companies
Salesforce customers using Gainsight apps (ShinyHunters / UNC6240)
Nov 2025Agent credentials and to
Anthropic disrupts GTG-1002 — the first reported large-scale AI-orchestrated espionage campaign
~30 global targets (tech firms, financial institutions, chemical makers, government agencies)
Nov 2025Long-lived AWS IAM user
Compromised AWS IAM credentials power a large EC2/ECS crypto-mining campaign
AWS customers running EC2 and ECS

Sourced from vendor postmortems, CISA, and reputable security press. TrustFix inventories, proves, and governs exactly these identities — and tells you, with signed proof, the moment one steps out of line.

Threat Feed — NHI & AI-agent security advisories | TrustFix