Today in AI: AI Agents Turn Exploits Into Autonomous Attacks — October 6, 2026

October 6, 2026 — today in AI.

1. GitLab AI Gateway Prompt Sandbox Escape Enables RCE

CVE-2026-90970, a critical flaw in GitLab's AI Gateway, allows authenticated Duo users to escape the prompt-template sandbox and execute commands on self-hosted instances. Organizations running GitLab Duo with self-hosted gateways must patch immediately to block authenticated RCE.

2. GitHub Copilot CLI Vulnerable to Cryptographic Context Injection

Adversa AI disclosed Cryptographic Context Injection (CCI) attacks against Copilot CLI, hiding malicious instructions in encrypted text to bypass prompt-injection detection. Developers using Copilot CLI for shell command generation face credential theft risk if the technique spreads into mainstream attack toolkits.

3. Six Weeks Post-Patch, MCP Flaw Still Exploited on US Servers

Despite patches from Google and JPMorgan, unpatched Model Context Protocol (MCP) implementations remain exposed on US infrastructure weeks after disclosure. The gap between patch release and deployment is widening as complexity increases, creating a persistent attack surface for MCP-dependent agents.

4. AI-Discovered Vulnerabilities Enable RCE at Higher Rates Than Human Finds

Google reported that vulnerabilities discovered by autonomous AI systems—like Hacktron AI's discovery of CVE-2026-1731 in BeyondTrust—show disproportionately high rates of unauthenticated RCE compared to manually discovered flaws. Security teams must assume AI-discovered CVEs warrant faster response times and higher severity assessment.