
AI Security Daily Issue #5 just dropped — and the AI gold rush just hit a brick wall: ✅ 1 Million AI Services Exposed — Intruder scanned Ollama, self-hosted LLMs, agent platforms & MCP servers. ✅ Fresh MCP RCE — CVE-2026-27203 in eBay API MCP Server: environment variable injection = instant remote code execution. Agent tool-calling just got another easy backdoor. ✅ Indirect Prompt Injection Still King — Google NotebookLM VRP payout proves file/context attacks are live and dangerous. Full issue with technical breakdowns, action items, and ready-to-copy security prompts for vibe programmers on @prmpted !
Post summary
The issue reports a fresh RCE vulnerability (CVE‑2026‑27203) in eBay API MCP Server via environment variable injection, alongside notes on AI service exposure.





