Novee and Miggo Security Reveal AI Vulnerabilities and Defenses
Novee researchers uncovered critical flaws in Google, OpenAI, and Anthropic AI systems while Miggo Security launched a defense-in-depth solution to mitigate such exploits.
At Black Hat USA 2026 and DEF CON 34 in Las Vegas, Novee and Miggo Security presented contrasting findings on the state of AI security. Novee revealed critical vulnerabilities in AI systems from Google, OpenAI, and Anthropic, specifically targeting Gemini CLI, Codex, and Claude Code. The research identified trust-handoff failures in agent workflows and a deterministic exploit in Google's Gemini CLI, which Google's security team assigned a maximum CVSS score of 10.0 before patching. Novee also uncovered remote code execution chains in enterprise Java middleware, illustrating how failures in the structures surrounding AI models can lead to secret exposure and supply chain compromises.
In response to the persistent gap between vulnerability disclosure and manual patching, Miggo Security launched its Defense-in-Depth Mitigation solution. The technology uses AI-generated controls at the network edge and within application runtimes to block exploits in minutes, potentially reducing the patch gap by up to 99%. To demonstrate the system, Miggo used a cluster of LiteLLM vulnerabilities, blocking a privilege escalation flaw at the edge and a remote code execution flaw inside the application via a WAF Copilot and runtime sensor.