Research
OWASP data: prompt injection still drives most agentic-AI security failures in production as MCP CVEs pile up
A June 11, 2026 report (Help Net Security, citing OWASP) finds prompt injection remains the dominant cause of agentic-AI security failures in production deployments. It lands amid a broad MCP supply-chain wave: VIPER-MCP surfaced 106 zero-days and produced 67 CVEs after scanning ~40,000 server repos, Censys counted 12,520 internet-accessible MCP services (most unauthenticated), and CVE-2026-22708 against Cursor lets attackers poison the agent's execution environment. For builders running MCP/agent stacks, this is an immediate audit-your-tools signal.
↳ Follow the thread