Agents
Adversa AI May 2026 Agentic Security Roundup: MemoryTrap, CrewAI CVE Chain, and Claude Code Deny-Rule Bypass
Adversa AI's May roundup aggregates three critical agentic AI security incidents: Cisco's MemoryTrap showing poisoned memory spreading across Claude Code sessions and users via npm postinstall hooks; four CrewAI CVEs (2026-2275/2285/2286/2287) chaining prompt injection to RCE, SSRF, and file reads through the Code Interpreter; and the Claude Code deny-rule bypass where 50+ subcommands silently disabled all security rules. Adversa recommends cryptographic agent identity, runtime isolation, and memory audit as immediate mitigations.
Source
↳ Follow the thread