Quick reference: Ongoing sources
- OWASP GenAI Security Project — quarterly Exploit Round-up Reports
- Vulnerable MCP Project —
vulnerablemcp.info— live MCP CVE database - MITRE ATLAS —
atlas.mitre.org - International AI Safety Report — annual; next likely Feb 2027
- Lakera (Check Point) blog — indirect prompt injection updates
- arXiv — search
cs.CRforagent security,prompt injection,MCP - CISA KEV catalog — confirms which AI/MCP CVEs are being actively exploited