Straiker-STAR-Labs-AI-Threat-Report-Vol-1-2026.md
ID: 8c66fee8-5b7c-4025-aa6d-884829fc3a8e
STIX ID: report--8c66fee8-5b7c-4025-aa6d-884829fc3a8e
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2026-07-26
Last Modified Date: 2026-07-26
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
STAR Labs' STAR‑Labs‑AI‑Threat‑Report‑Vol‑1 (2026) warns that agentic AI introduces a new, high‑risk attack surface where AiPT adversaries exploit Language‑Augmented Vulnerabilities (LAVA) across four architectural layers (application, model, tools/MCP, data). The report quantifies large-scale MCP and tool risks (17,651+ MCP servers tracked, 4,242 vulnerable servers, 130k+ tools), documents 1,700+ real exploitation engagements including infostealer campaigns (fake Claude Code), and prescribes the STAR Framework controls—treat external content as untrusted, narrow permissions, require approvals for irreversible actions, and deploy agent‑on‑agent runtime monitoring.
