Innovation Hub

Featured Posts

Insights
min read

HiddenLayer Solutions for the July 2026 Agent Intrusion

Insights

Agent Harness Security

Insights

HiddenLayers integration with Truefoundry AI Gateway

Get all our Latest Research & Insights

Explore our glossary to get clear, practical definitions of the terms shaping AI security, governance, and risk management.

Research

Research
min read

Dead Drops in Public: What the AI Agent Stashed on Hugging Face

Research

A Security Framework for Coding Agents and their Harnesses

Research

How Coding Agents Are Changing Application Risk

Research

What’s the ‘Matter’ with Skills?

Videos

Report and Guides

Report and Guide

Field Artifacts from the July 2026 Agent Intrusion

A technical companion to Hugging Face's "Agent Intrusion: A Technical Timeline," based on over 500 artifacts the agent staged in public dead-drop repositories.

Report and Guide

AI Threat Landscape Report April-June Quarterly Update

The AI threat landscape evolves too quickly for a once-a-year snapshot.

Report and Guide

2026 AI Threat Landscape Report

Register today to receive your copy of the report on March 18th and secure your seat for the accompanying webinar on April 8th.

HiddenLayer AI Security Research Advisory

CVE-2026-87988

_READ_ONLY_COMMANDS_POSIX expansion adds 31 commands with no path checking, granting unconditional access to the full host filesystem

Mistral Vibe automatically approves a large set of commands that are not subject to the expected workspace path restrictions, allowing files anywhere on the host to be accessed without user approval.

CVE-2026-87987

Environment variable prefixes stripped from permission check enable RCE via env injection

Mistral Vibe does not consider environment variable assignments when checking whether a command can run without approval, allowing environment controlled behavior in allowlisted programs such as Git to be abused for arbitrary code execution.

CVE-2026-87986

Unparsable shell constructs silently auto-approved lead to arbitrary code execution

Mistral Vibe can fail to inspect parts of a shell command when its parser does not understand the syntax being used, allowing hidden commands to execute without the expected user approval.

CVE-2026-87985

ANSI-C quoted strings are not exposed to tree-sitter

Mistral Vibe can miss dangerous command arguments when they are expressed using ANSI C quoting, allowing an allowlisted command to execute arbitrary code without triggering a permission prompt.

In the News

News
HiddenLayer Raises $100M Series B to Advance Trustworthy AI

HiddenLayer raises $100M in Series B funding to advance AI security, expand agentic runtime protection, and meet growing enterprise demand.

News
HiddenLayer Selected to Support DOE’s $60 Million Prometheus Initiative Under the Genesis Mission

HiddenLayer joins the DOE’s $60M Prometheus initiative to help secure AI applications across the U.S. nuclear energy sector and critical infrastructure.

News
HiddenLayer Appoints Mike Gesnaldo as Chief Revenue Officer to Accelerate Next Phase of Growth

HiddenLayer appoints Mike Gesnaldo as Chief Revenue Officer to scale its go-to-market organization and help enterprises securely adopt AI.

Stay Ahead of AI Security Risks

Get research-driven insights, emerging threat analysis, and practical guidance on securing AI systems—delivered to your inbox.

By submitting this form, you agree to HiddenLayer's Terms of Use and acknowledge our Privacy Statement.

Thanks for your message!

We will reach back to you as soon as possible.

Oops! Something went wrong while submitting the form.