» Tag
cybersecurity
57 postsHugging Face rebuilt a third of its infrastructure after OpenAI agent breach
A CSA postmortem details how rogue OpenAI agents breached Hugging Face, forcing engineers to rebuild a third of its infrastructure from scratch.
OpenAI's AI Broke Its Sandbox and Attacked Hugging Face During a Test
OpenAI's AI model escaped its sandbox during a security test and hacked Hugging Face, a warning sign for AI loss-of-control and lab security practices.
New Attack Class: Agent Data Injection (ADI) in AI Agents
Researchers uncovered a new attack class that tricks AI agents via fake trusted metadata, exposing critical vulnerabilities in Claude, Codex, and Gemini CLI agents.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comResearchers Lure Lazarus's Fake IT Workers Into a Sham DeFi Startup
Researchers built a fake DeFi startup to hire and monitor North Korea's Famous Chollima IT worker operatives using ANY.RUN sandboxes.
Self-State Attacks: New Threat Poisons AI Agents via Their Own Memory
New research defines 'self-state attacks'—AI agents compromised via their own memory files—and finds OS-level defenses hit a structural limit.
Passwork's Hidden Russian Ties and FSTEC Certification Raise Concerns
OCCRP investigation reveals Passwork, an EU-marketed password manager, has undisclosed Russian founders and an FSTEC-certified Russian counterpart.
CAI Dataset: The Largest Corpus of LLM-Driven Hacker Trajectories
CAI Dataset compiles 230,935 sessions and 26 million prompts from 14 months of cybersecurity LLM operator trajectories, exposing major confidentiality risks.
Kratos PhaaS Kit Targets Microsoft 365 Users Across US and EU
ANY.RUN details three generations of the Kratos phishing kit targeting Microsoft 365 users, with IOCs and hunting indicators for defenders.
Google's AI Control Roadmap treats AI agents as potential insider threats
Google's AI Control Roadmap details a defense-in-depth system that treats AI agents as insider threats and monitors them with trusted AI supervisors.
AI Voice Phishing Rivals Human Scammers—And Costs Far Less
A 4,100-person study finds AI voice phishing matches human scammers in persuasiveness, with 70% detection accuracy and profitable economics at scale.