The AIDR Brief
Agentic AI Security Research & Analysis
Research, intelligence, and field notes from the Manifold team.

- Thought Leadership
A one-time approval can't govern what your agents run
Oct 1, 2026
Oleksandr YaremchukCTO & Co-Founder

- Research
Jev, system one models, and how to use them in security
Oct 1, 2026
Cody NashResearcher
Markus GierlingerSecurity Researcher

- Research
Rogue agents targeted a second Australian health dashboard, urlscan.io index shows
Sep 25, 2026
Ax SharmaHead of Research

- Research
Over 350,000 GitHub files cite placeholder domains serving scams
Sep 24, 2026
Cody NashResearcher

- Product
Blocking is the only answer most security tools have. "Ask" lets the developer decide.
Sep 23, 2026
Neal SwaelensCEO & Co-Founder

- Research
The third-party[.]com domain is serving a ClickFix lure to Windows users
Sep 23, 2026
Ax SharmaHead of Research

- News
- Product
AI Agents Moved Into the Browser, Make Sure Your Governance Follows
Sep 16, 2026
Neal SwaelensCEO & Co-Founder

- News
Joe Sullivan Joins Manifold's Board
Sep 9, 2026
Neal SwaelensCEO & Co-Founder

- Research
GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Sep 1, 2026
Francisco RosalesOffensive Security Engineer

- Research
OpenAI & Hugging Face: Why The Chain-of-Thought Police Won't Save You
Aug 28, 2026
Cody NashResearcher

- Research
What to think about curl | bash now that AI agents run it.
Aug 19, 2026
Ax SharmaHead of Research
Cody NashResearcher

- Research
Cursor CLI Ran Untrusted Repository Code With the Sandbox Switched Off
Aug 10, 2026
Francisco RosalesOffensive Security Engineer

- Research
When a conversation wanders, do an agent's guardrails slip?
Aug 5, 2026
Cody NashResearcher

- Research
77 "evil twin" Open VSX extensions: 19 copy private repo and CI data to a new domain
Aug 4, 2026
Ax SharmaHead of Research
Cody NashResearcher

- Thought Leadership
OpenAI and Anthropic Both Disclosed the Same Thing: The Agent Is the Threat Actor Now
Jul 31, 2026
Nate DemuthChief Architect

- Research
Anyone with an account could run commands on PewDiePie's AI workspace (CVSS 9.9)
Jul 30, 2026
Francisco RosalesOffensive Security Engineer

- Thought Leadership
Lethal Trifecta Noise: Why it fits every agent you deploy
Jul 29, 2026
Nate DemuthChief Architect

- Research
The "Restricted" Deployment That Wasn't: Two Access-Control Bugs in community-built mcp-atlassian
Jul 27, 2026
Francisco RosalesOffensive Security Engineer

- Research
A beaconing counterfeit extension on the VS Code Marketplace: the 'Markdown All Pro' extension
Jul 22, 2026
Ax SharmaHead of Research
Cody NashResearcher

- Research
When Your AI Reviewer Works for the Attacker: A Confused-Deputy Bug in Microsoft's Azure DevOps MCP Server
Jul 21, 2026
Francisco RosalesOffensive Security Engineer

- Thought Leadership
Intent Drift Noise: Why session-level intent drift falls apart in production
Jul 16, 2026
Nate DemuthChief Architect

- Research
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail
Jul 14, 2026
Ax SharmaHead of Research

- Research
Scope Squatting: Those @openclaw and @clawhub Plugins Aren't Officially Theirs
Jun 19, 2026
Ax SharmaHead of Research

- Research
CVE-2026-52024, CVE-2026-52025: We Bypassed Two of Cline's Safety Checks to Run Code (4.2M Installs)
Jun 17, 2026
Ax SharmaHead of Research

- Thought Leadership
Is Prompt Injection a Vulnerability?
Jun 11, 2026
Ax SharmaHead of Research

- Thought Leadership
10,000 Vulnerabilities in 30 Days. Picture This Threat Inside Your Stack.
Jun 5, 2026
Oleksandr YaremchukCTO & Co-Founder

- Research
CVE-2026-54052: A wrong number in n8n-mcp leaked your neighbor's credentials (CVSS 9.6)
Jun 4, 2026
Ax SharmaHead of Research
Francisco RosalesOffensive Security Engineer

- Thought Leadership
What the AI Village Disasters Reveal About Runtime Security
Jun 1, 2026
Neal SwaelensCEO & Co-Founder

- Research
When "Read-Only Mode" Isn't: CVE-2026-46519 in mcp-server-kubernetes
May 18, 2026
Ax SharmaHead of Research
Francisco RosalesOffensive Security Engineer

- Research
One AI Security Scanner Flagged 40% of Skills as Malicious. Most Were Fine.
May 14, 2026
Ax SharmaHead of Research

- Product
Manifold Adds MCP Servers to Manifest Supply Chain Intelligence
May 12, 2026
Oleksandr YaremchukCTO & Co-Founder
Neal SwaelensCEO & Co-Founder

- Research
30 ClawHub Skills Are Quietly Recruiting Your AI Agent Into a Crypto Swarm
Apr 28, 2026
Ax SharmaHead of Research

- Research
An OpenClaw Skill With An SVG Can Steal Your Cookies
Apr 22, 2026
Ax SharmaHead of Research

- Research
The Gateway Gap: Why AI Agent Security Needs More Than a Chokepoint
Apr 16, 2026
Oleksandr YaremchukCTO & Co-Founder
Nate DemuthChief Architect

- Research
Two Git Commands Fooled Claude Into Merging Malicious Code
Apr 15, 2026
Ax SharmaHead of Research
Oleksandr YaremchukCTO & Co-Founder

- Product
Introducing Manifest: Supply Chain Intelligence for the AI Agent Ecosystem
Apr 14, 2026
Oleksandr YaremchukCTO & Co-Founder
Neal SwaelensCEO & Co-Founder

- Research
Non-Adversarial Agent Harm: The Overlooked Insider Threat
Apr 12, 2026
Neal SwaelensCEO & Co-Founder

- Research
Why Your EDR Has No Clue What Your Agents Are Up To
Apr 7, 2026
Nate DemuthChief Architect
Neal SwaelensCEO & Co-Founder

- Research
Why AI Guardrails Can’t Secure Your Agents: The Classification Fallacy
Mar 31, 2026
Neal SwaelensCEO & Co-Founder
Oleksandr YaremchukCTO & Co-Founder

- News
Manifold Raises $8M to Secure AI Agents on Endpoints
Mar 18, 2026
Manifold TeamThe Team

- Research
The Sandbox Illusion: How Do You Isolate Agents That Think Outside the Box?
Mar 18, 2026
Neal SwaelensCEO & Co-Founder
Oleksandr YaremchukCTO & Co-Founder


