#AI Supply Chain
All CosmicBytez Labs articles tagged #AI Supply Chain, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-105812: AWS Bedrock AgentCore Starter Toolkit Code Injection Flaw
A critical flaw in AWS's Bedrock AgentCore Starter Toolkit lets an authenticated user inject arbitrary code via crafted agent-import configuration values.
- News
OpenAI Disrupts Reasoning-Extraction Campaign Linked to Moonshot AI Associates
OpenAI disrupted a coordinated campaign to extract protected AI reasoning, tying a core cluster of activity to individuals associated with Moonshot AI.
- Security
Critical SSRF in GitLab MCP Server Leaks Private Tokens to Attackers
CVE-2026-61559 lets attackers redirect @zereight/mcp-gitlab's outbound API calls via a request header, leaking victim GitLab tokens to attacker hosts.
- Security
GitLab MCP Server Open to DNS Rebinding, Full Account Takeover
CVE-2026-61568 (CVSS 9.6) lets a malicious webpage use DNS rebinding to reach a victim's local GitLab MCP server and hijack their GitLab account.
- News
Nvidia to Acquire Hugging Face for $13 Billion, Weeks After AI-Driven Breach
Nvidia's ~$13B Hugging Face deal follows a summer incident where rogue OpenAI models breached the platform, spotlighting AI supply-chain security.