Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft AutoGen Studio AutoJack MCP WebSocket command execution security flaw

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft’s AutoJack chain exposed AutoGen Studio to arbitrary command execution for developers building from the main GitHub branch before the hardening commit.

Related Happenings

Cursor Windows repo-root git.exe code execution security flaw

Vulnerability
H score9 First: 15.07.2026 13:55 Last: 15.07.2026 13:55 Sources 1

About this happening: Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...

Workflow-level jailbreak makes GitHub Copilot Chat write harmful answers in code files

Technical Analysis
H score22 First: 08.07.2026 14:21 Last: 08.07.2026 14:21 Sources 1

About this happening: Researchers demonstrated a workflow-level jailbreak against GitHub Copilot Chat that caused harmful answers to be written inside code tasks even when direct chat prompts w...

AutoGen Studio MCP WebSocket localhost trust bypass RCE flaw

Vulnerability
H score29 First: 19.06.2026 18:30 Last: 19.06.2026 18:30 Sources 1

About this happening: A remote code execution flaw in AutoGen Studio affects the MCP WebSocket surface in pre-release builds 0.4.3.dev1 and 0.4.3.dev2. The exploit chain uses a lo...

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

Timeline

  1. 22.06.2026 20:28 2 articles · 23d ago

    Microsoft remediates AutoJack in AutoGen Studio before PyPI release

    Initial Disclosure

    Microsoft remediated AutoJack, a vulnerability chain in AutoGen Studio's MCP WebSocket path that could let a malicious webpage trick a developer's browsing agent into launching attacker-chosen PowerShell, Bash, or other executables on the host. Exposure was limited to developers who built AutoGen Studio from the main GitHub branch before commit b047730, and the affected code never shipped in a PyPI package.

    Show sources