Straiker’s STAR team leads research in AI security where they are uncovering vulnerabilities in LLMs and agentic AI, sharing discoveries, contributing to open-source, and building the guardrails that protect tomorrow’s autonomous systems and applications.
Straiker AI & Security Research
.avif)
Agentic AI Security Research & Insights
Explore Straiker STAR’s latest findings on LLM vulnerabilities, agentic AI threats, and runtime guardrails. Access blogs, frameworks, and downloadable reports that define the future of AI-native security.
Fable to Haiku: How a Malicious Repo Tricked Claude Code Into Running Malware
A malicious repo downgraded Claude Code’s review from Fable to Haiku, steered the agent away from the payload, and turned a routine test run into malware execution.


Escape from Pod 9: How Prompt Injection Turned an AI SRE Agent into a Kubernetes Ransomware Attack Vector
See how poisoned OpenTelemetry telemetry manipulated an AI SRE agent into deploying a privileged Kubernetes container, escaping to an EKS host, and executing ransomware.

The AI Agent Execution Gap: Securing What Happens After an Agent Decides to Act
Learn how AI agent runtime security uses context to protect tool calls, MCP servers, Skills, APIs, and agent actions, securing agents before they create impact.

Agentic Security Needs Its Own Framework: The Straiker STAR Framework
In agentic AI, the model behaves and the user is legitimate. The weapon is the context the agent reads. Here is why we built the Straiker STAR Framework to map the agentic attack surface, and how it supplements the NIST AI RMF and OWASP.

Ghostfabric: How An AI Coding Agent Was Tricked Into Exfiltrating Data Over VXLAN
How did Google Antigravity exfiltrate data? GhostFabric shows how an AI coding agent running Gemini 3.1 Pro exploited a cloud internal network using VXLAN.


Andromeda: One Researcher's Agentic AI Payload Framework
Andromeda is an open-source red team framework by Straiker. It uses LLM agents to dynamically compile and execute position-independent payloads in live memory.

Fake Claude Code, Real Malware: Inside the Campaign Targeting AI Developers
AI tools are the new attack vector. Discover how the ACRStealer campaign uses fake Claude Code and JetBrains pages to steal developer API keys and crypto.


NomShub: Weaponizing Cursor's Remote Tunnel Through Indirect Prompt Injection and Sandbox Breakout
Are your AI coding agents secure? Read STAR Labs' deep dive into NomShub, a new exploit weaponizing Cursor's remote tunnel for persistent system compromise.


Claude Code Source Leak: With Great Agency Comes Great Responsibility
Anthropic exposed 512K lines of Claude Code via npm. Read our analysis on what the leak reveals about context poisoning, sandbox bypasses, and AI threats.


Built on ClawHub, Spread on Moltbook: The New Agent-to-Agent Attack Chain
Straiker uncovers a new agent-to-agent attack chain where malicious Claude Skills on ClawHub use fake AI personas on Moltbook to deploy crypto scams.


SmartLoader Clones Oura Ring MCP to Deploy Supply Chain Attack
A sophisticated supply chain attack targeting the MCP ecosystem used fake GitHub accounts and a cloned Oura Ring server to infiltrate developer environments with credential-stealing malware.


OWASP Just Released Its First Top 10 for Agentic AI and Here's What You Need to Know
What are the biggest security risks in Agentic AI? This guide breaks down the official OWASP Top 10 for Agentic Applications and how to secure AI workflows.


From Inbox to Wipeout: Perplexity Comet’s AI Browser Quietly Erasing Google Drive
Protect your enterprise from agentic AI risks. Straiker reveals how prompt injection turns Perplexity Comet into a Google Drive wiper and how to stop it.


Cyberspike Villager – Cobalt Strike’s AI-native Successor
Straiker exposes Villager, a Chinese-based AI-native pentesting framework. Read our threat analysis on how this Cobalt Strike successor automates cyberattacks.


The Silent Exfiltration: Zero‑Click Agentic AI Hack That Can Leak Your Google Drive with One Email
Straiker reveals how zero-click exploits can hijack AI agents to exfiltrate Google Drive data, no user interaction needed. See how attack chains form, why autonomy is dangerous, and how runtime guardrails catch what others miss.


Detecting Autonomous Chaos: Github MCP Exploit
Stop AI agents from exposing sensitive data. Explore the GitHub MCP exploit POC and see why traditional alignment checks fail where Straiker Defend AI succeeds.


Weaponizing Wholesome Yearbook Quotes to Break AI Chatbot Filters
See how 20+ top AI chatbots (ChatGPT, Claude, Gemini) fell victim to prompt injections using the "Yearbook Attack." Explore LLM security risks and solutions.


Agentic Danger: DNS Rebinding Exposes Internal MCP Servers
The Straiker AI Research (STAR) team found a new attack that we’re calling MCP rebinding attack, which is a combination of DNS rebinding and MCP over Server-Sent Events (SSE) protocol.


Rethinking Security in the AI Age
Is your AI application vulnerable to LAVA, memory poisoning, or prompt injection? Read an AI researcher’s guide to securing the full agentic workflow stack.

Securing Agentic AI in a Multi-Agent World
Traditional security can’t protect autonomous AI. Explore threat modeling for multi-agent workflows, including instruction manipulation and resource exhaustion.


Meet Straiker’s STAR Team
STAR is more than a research lab—it’s a team of innovators dedicated to securing agentic AI. Meet the experts publishing breakthroughs, contributing to open-source, and collaborating with the wider AI security community.

Our Approach to Agentic AI Security Research
Straiker’s STAR team advances AI security with a focus on impact and openness. We investigate vulnerabilities in LLMs and autonomous agents, publish frameworks that guide the industry, and contribute to open-source guardrails. Our mission: make agentic AI safer for enterprises and the world.
AI-native Thinking
Our researchers embrace both the promise and the pitfalls of AI. Securing non-deterministic systems demands a fresh approach—one that fuses proven security principles with new methods built from the ground up for agentic AI.
Proactive Defense
We don’t just study AI vulnerabilities—we weaponize our findings to build defenses. Straiker’s red teaming and runtime guardrails are informed by STAR research, ensuring every safeguard is tested against the latest real-world threats.
Practical Impact
Our research is grounded in reality. We turn complex discoveries into actionable guardrails, benchmarks, and frameworks that security and engineering teams can apply today.
A New World, A New Vocabulary
AI is redefining what’s possible. As we navigate this frontier, new words emerge to describe its systems, risks, and discoveries. This glossary helps you make sense of the evolving language of intelligence.

Securing the future, so you can focus on imagining it
Get FREE AI Risk Assessment
.avif)







