Logo
Log in
Subscribe
Logo
Oliver Buchannon
Amine Raji

I’m Amine Raji, founder of Molntek.com and a specialist in AI security for organizations deploying agentic and LLM-powered systems.

Read-only held for the entire intrusion. The agent still walked out with a map of the estate.

Aug 4, 2026

•

8 min read

Read-only held for the entire intrusion. The agent still walked out with a map of the estate.

[AI Sec Intel] #23 | Anthropic reviewed 141,006 evaluation runs and found three real companies breached. Two of them had no idea until Anthropic called. AWS named read-only as the containment answer the same day.

Amine Raji
Amine Raji
An attacker ran an agent in YOLO mode against a finance ministry.

Jul 29, 2026

•

6 min read

An attacker ran an agent in YOLO mode against a finance ministry.

[AI Sec Intel] #22 Researchers caught an autonomous agent enumerating a government network mid-operation, because the attacker left its output directory on the internet. Thirty-seven companies formed an alliance. And two package registries decided the best defense is waiting.

Amine Raji
Amine Raji
OpenAI's model breached Hugging Face to win a benchmark

Jul 24, 2026

•

6 min read

OpenAI's model breached Hugging Face to win a benchmark

[AI Sec Intel] #21 It was isolated from the internet except for one package proxy. That was enough. Then the defenders found their own AI wouldn't look at the evidence.

Amine Raji
Amine Raji
466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo

Jul 17, 2026

•

6 min read

466 million lines reviewed in 20 hours. Both offense and defense just went machine-tempo

[AI Sec Intel] #20 A government ran 50 agents across its whole code estate. Two part-time hackers shipped a profitable hackbot. Agent identity became a product category. The common thread: the credential is the target.

Amine Raji
Amine Raji
One polite word bypassed the guardrails. The private repos leaked anyway

Jul 13, 2026

•

7 min read

One polite word bypassed the guardrails. The private repos leaked anyway

[AI Sec Intel] #19 GitHub's agentic workflows leaked private repos to anyone who could open an issue. An AI agent ran a ransomware attack nearly end to end. And Kubernetes ops agents went mainstream. One thread ties all three.

Amine Raji
Amine Raji
On July 28, MCP changes shape

Jul 7, 2026

•

6 min read

On July 28, MCP changes shape

[AI Sec Intel] #18 The new MCP spec goes final July 28 and moves security from the protocol to the endpoint. Plus: new research explains why prompt injection works, and it's not what you think.

Amine Raji
Amine Raji
Your agents have no idea who they are. Attackers are counting on it.

Jul 2, 2026

•

8 min read

Your agents have no idea who they are. Attackers are counting on it.

[AI Sec Intel] #17 Identiverse 2026 named agent identity the defining problem of the year. Step Finance lost $27M because its agents could move money without asking. The fix is testable. Here's the test.

Amine Raji
Amine Raji
I let an agent rewrite my code while I slept. The scary part wasn't the bill

Jun 29, 2026

•

6 min read

I let an agent rewrite my code while I slept. The scary part wasn't the bill

[AI Sec Intel] #16 OWASP's agentic security report now reads like an incident log, not a threat catalog. The same permission model powering autonomous coding loops is the one attackers exploit.

Amine Raji
Amine Raji
AI Security Intelligence — Special Issue

Jun 12, 2026

•

4 min read

AI Security Intelligence — Special Issue

I've been quietly shipping. Six assets are live, they're all free, and most of you have never seen them.

Amine Raji
Amine Raji
[AI Sec Intel] #15 One character in a header bypasses auth on millions of AI servers.

Jun 9, 2026

•

5 min read

[AI Sec Intel] #15 One character in a header bypasses auth on millions of AI servers.

CVE-2026-48710 turns a malformed Host header into an auth bypass across the production AI stack. Here's how to check if you're exposed in five minutes.

Amine Raji
Amine Raji
[AI Sec Intel] #14 Your coding agent's approval prompt is lying to you.

Jun 4, 2026

•

5 min read

[AI Sec Intel] #14 Your coding agent's approval prompt is lying to you.

SymJack and TrustFall broke every major AI coding agent this month: Claude Code, Cursor, Gemini, Copilot, Codex. The dialog you click through doesn't say what you're approving. Here's what to do.

Amine Raji
Amine Raji
[AI Sec Intel] #13 Six governments just told you how to secure AI agents. Here's the part that's actually useful

May 31, 2026

•

6 min read

[AI Sec Intel] #13 Six governments just told you how to secure AI agents. Here's the part that's actually useful

The progressive-autonomy model, the identity-first mandate, and why a regex blocklist turned an AI agent into a remote shell.

Amine Raji
Amine Raji

mcp

+2

[AI Sec Intel] #12 — Claude Mythos, SAFE-MCP, MCPShield: the week the research caught up with the threat

May 20, 2026

•

7 min read

[AI Sec Intel] #12 — Claude Mythos, SAFE-MCP, MCPShield: the week the research caught up with the threat

Claude Mythos found thousands of zero-days in 20 hours. Three new MCP research papers landed. And no existing defense covers the full attack surface.

Amine Raji
Amine Raji
[AI Sec Intel] #11 — MCP servers just tripled. Here's the full attack map

May 9, 2026

•

6 min read

[AI Sec Intel] #11 — MCP servers just tripled. Here's the full attack map

1,467 exposed servers. 9 of 11 registries poisoned. Memory that spreads across users. The week in MCP security.

Amine Raji
Amine Raji
[AI Sec Intel] #10 — MCP servers trust every caller by default. Here's the checklist that closes the gap.

Apr 29, 2026

•

3 min read

[AI Sec Intel] #10 — MCP servers trust every caller by default. Here's the checklist that closes the gap.

New research confirms MCP servers trust every request by default. Here's what to do before it becomes someone else's exploit

Amine Raji
Amine Raji
[AI Sec Intel] #9 — Eight agent exploits in Q1. 200k vulnerable MCP servers and Anthropic won't fix the protocol.

Apr 21, 2026

•

3 min read

[AI Sec Intel] #9 — Eight agent exploits in Q1. 200k vulnerable MCP servers and Anthropic won't fix the protocol.

A persistent context window is a persistent attack surface. Eight production incidents this quarter prove it.

Amine Raji
Amine Raji
[AI Sec Intel] #8 — Closed Agent Harness = threat model blind spot

Apr 14, 2026

•

6 min read

[AI Sec Intel] #8 — Closed Agent Harness = threat model blind spot

I built a 3-agent coding system this week. First control I added: repo isolation on the write-capable agent.

Amine Raji
Amine Raji
[AI Sec Intel] #7 — 97% expect an AI agent breach this year

Apr 8, 2026

•

5 min read

[AI Sec Intel] #7 — 97% expect an AI agent breach this year

But only 6% of the security budgets cover it

Amine Raji
Amine Raji
[AI Sec Intel] #6 — Trivy compromised. LiteLLM backdoored. Your CI pipeline is the new attack surface.

Mar 31, 2026

•

7 min read

[AI Sec Intel] #6 — Trivy compromised. LiteLLM backdoored. Your CI pipeline is the new attack surface.

The payload ran as a systemd service. The Trivy scan still returned green. Nobody noticed.

Amine Raji
Amine Raji
[AI Sec Intel] #5 — 28 out of 30 agent projects. Zero per-agent identity. Zero revocation.

Mar 24, 2026

•

7 min read

[AI Sec Intel] #5 — 28 out of 30 agent projects. Zero per-agent identity. Zero revocation.

The .env file is not an identity system. The ecosystem just forgot. Plus a CVSS 9.8 with no patch.

Amine Raji
Amine Raji
[AI Sec Intel] #4 - Three attack papers dropped this week. All point to the same architectural flaw.

Mar 16, 2026

•

5 min read

[AI Sec Intel] #4 - Three attack papers dropped this week. All point to the same architectural flaw.

99% guardrail bypass, 95% RAG poisoning, and the one fix that addresses both.

Amine Raji
Amine Raji
[AI Security Intelligence] #3 — I Red-Teamed My Own Agent Stack, PleaseFix Hijacks Browsers Through Calendar Invites

Mar 9, 2026

•

6 min read

[AI Security Intelligence] #3 — I Red-Teamed My Own Agent Stack, PleaseFix Hijacks Browsers Through Calendar Invites

One line in a Dockerfile stopped three containers, exfiltrated a full inventory, and the AI reported: “The image is safe to use.”

Amine Raji
Amine Raji
[AI Security Intelligence] #2 — Claude Code Supply Chain RCE, AI-Powered FortiGate Blitz, Infostealers Now Harvest AI Agent Souls

Mar 2, 2026

•

17 min read

[AI Security Intelligence] #2 — Claude Code Supply Chain RCE, AI-Powered FortiGate Blitz, Infostealers Now Harvest AI Agent Souls

When your AI coding assistant's config files become an attack vector, a script kiddie with ChatGPT breaches 600 firewalls, and malware evolves to steal your agent's entire identity

Amine Raji
Amine Raji
[AI Security Intelligence] #1 — DockerDash MCP Takeover, vLLM CVSS 9.8 RCE, Cisco State of AI Security 2026

Feb 23, 2026

•

11 min read

[AI Security Intelligence] #1 — DockerDash MCP Takeover, vLLM CVSS 9.8 RCE, Cisco State of AI Security 2026

When image metadata becomes remote code execution, your AI inference servers are pre-auth targets, and Cisco confirms lab attacks have gone live.

Amine Raji
Amine Raji

AI Security Intelligence

Help CTOs and security teams understand the attack surface they’re creating when they deploy AI, and how to close it before it becomes an incident.

© 2026 AI Security Intelligence.
beehiivPowered by beehiiv