AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

16:27 · August 5, 2026 · Hacker News AI Section

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

Summary

HashiCorp, Veeam, and the Django Software Foundation have issued patches addressing eleven vulnerabilities across their respective products, with the most severe involving a CVSS 10.0 cross-tenant isolation failure in the Terraform MCP Server. The server, which enables AI assistants to interact with Terraform through the Model Context Protocol, exposed credentials across users when operated in multi-user Streamable HTTP mode. In stateless configurations the underlying MCP library failed to generate unique session identifiers, allowing one tenant’s cached Terraform token to be reused for subsequent requests regardless of the supplied credentials. A related stateful-mode flaw permitted session-ID reuse to invoke another user’s client, while a third issue enabled server-side request forgery by accepting attacker-controlled addresses through query parameters that bypassed header validation.

Veeam addressed four vulnerabilities in the Service Provider Console, the multi-tenant management interface used by hosting providers to oversee customer backups. Two critical flaws in builds prior to 9.3.0.35057 included an unauthenticated credential exposure rated 9.5 under CVSS 4.0 and a separate unauthenticated memory-exhaustion denial-of-service vector. Additional high-severity issues allowed temporary elevation to Portal Administrator privileges and exposed proxied appliance APIs during administrator session initialization. The fixes apply to all version 9 releases up to 9.2.1.33875; the new build was released on 29 July and detailed in an advisory published 4 August.

Django released versions 6.0.8 and 5.2.17 to correct four issues, one of which received a high severity rating under the project’s own policy. The flaw resided in GeoDjango spatial lookups, which accepted string or dictionary values that could be passed to GDALRaster, potentially resulting in file writes or outbound network requests depending on the raster driver. The documented attack path requires a staff account holding view permission on a model that contains a spatial field. The remaining three vulnerabilities were rated lower; older unsupported branches were not assessed for impact.

None of the advisories report active exploitation, and as of 5 August 2026 none of the CVEs appear in CISA’s Known Exploited Vulnerabilities catalog. Operators are advised to apply the updates promptly, restrict network exposure of the Terraform MCP Server’s HTTP listener where upgrades are delayed, and treat MCP session identifiers as sensitive material.

Why it matters

This article details critical vulnerabilities in infrastructure tools used to deploy and manage AI systems, specifically the Terraform MCP server which connects AI assistants to infrastructure. Security professionals in the Dutch AI market must urgently assess their exposure to prevent cross-tenant credential reuse and potential remote code execution.

More in this beat
cisaDjangoHashiCorpmodel-context-protocolterraformthreat-and-vulnerability-updatesVeeam
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

20:23 · July 20, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.

Relevance 85 · Audience 90

Identity Lifecycle Management Wasn't Built for AI Agents

13:30 · July 2, 2026

Identity Lifecycle Management Wasn't Built for AI Agents

This is highly relevant for security and privacy professionals in the Netherlands as the adoption of autonomous AI agents grows. Proper identity and access management for AI is essential to maintain compliance with EU regulations like the AI Act and GDPR, preventing unauthorized data access and lateral movement.

Relevance 85 · Audience 95

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

19:46 · June 30, 2026

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

This article is highly relevant for security and privacy professionals as it exposes a novel attack vector against AI agents that bypasses traditional security alarms. Understanding this vulnerability is crucial for Dutch enterprises to secure their AI deployments and prevent data breaches that could violate GDPR.

Relevance 90 · Audience 95

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

08:26 · June 9, 2026

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

This article is highly relevant for security professionals managing AI infrastructure, as LiteLLM is a widely used tool for routing LLM API calls. Dutch enterprises utilizing LiteLLM must patch immediately to prevent remote code execution and secure their AI deployments against active threats.

Relevance 85 · Audience 95

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

18:59 · August 20, 2026

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

This article highlights a critical evolution in offensive AI capabilities targeting industrial control systems (ICS) like Siemens S7 PLCs, which are heavily utilized in Dutch critical infrastructure and manufacturing. Security professionals in the Netherlands must understand these AI-driven threat vectors to defend operational technology (OT) environments effectively.

Relevance 85 · Audience 95

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

Relevance 85 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

How Cloudflare detects MCP traffic and helps secure it

15:12 · August 14, 2026

How Cloudflare detects MCP traffic and helps secure it

Directly addresses AI security risks from agent-driven tool calls via MCP, with actionable network controls usable by Dutch enterprises on managed paths. Strong EU relevance through privacy controls, logging, and compliance with data protection needs. Targets security professionals managing AI deployments.

Relevance 85 · Audience 90

DIA’s artificial intelligence chief envisions ‘agent-to-agents’ interactions that support military operations

00:27 · August 14, 2026

DIA’s artificial intelligence chief envisions ‘agent-to-agents’ interactions that support military operations

This article is highly relevant for defense strategists and technologists as it outlines the US Defense Intelligence Agency's roadmap for multi-agent AI systems in combatant commands. Understanding these developments is crucial for Dutch and NATO defense professionals to ensure interoperability, align military AI doctrines, and develop compliant, ethical AI guardrails.

Relevance 75 · Audience 90

AI Exposes Enterprise Data via Prompt Injection

17:19 · August 13, 2026

AI Exposes Enterprise Data via Prompt Injection

Directly addresses AI-specific security risks and privacy threats with actionable recommendations on data governance and access controls, highly relevant for Dutch/EU security professionals managing AI deployments under GDPR.

Relevance 85 · Audience 90