» Tag
security
518 postsSophos study: AI coding agents look like attackers to a SIEM
Sophos telemetry shows Claude Code, Cursor, and Codex trigger SIEM alerts for credential access and evasion during normal, benign operation.
CCIP's Router Pattern: One Immutable Contract Per Chain
A look at Chainlink CCIP's onchain architecture: how an immutable per-chain Router, upgradable OnRamp/OffRamp, and lane-based rate limits redesign cross-chain security.
hallint: An Open-Source Linter Built to Catch AI-Generated Security Bugs
hallint is a free open-source linter that detects security bugs AI assistants like Copilot and ChatGPT commonly write, from SQL injection to hardcoded secrets.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comCargo Symlink Flaw Disclosed as CVE-2026-5223
CVE-2026-5223: Cargo mishandled symlinks in third-party registry tarballs, risking cache overwrites; fixed in Rust 1.96.0.
LLM Agents Can Easily Tamper With Their Own Execution Traces
New research finds that LLM coding agents can delete or rewrite their own execution logs via direct requests, malicious skills, and reward hacking.
Unattended AI Agent Framework Patches Flaws Across 2.1M-Star Repos
Aeon, an MIT-licensed agent framework running entirely on GitHub Actions, has patched security flaws across repos with 2.1M combined stars.
Asahi Linux Works Around Missing PSCI on Apple Silicon
Asahi Linux details a UEFI-based workaround for missing PSCI on Apple Silicon, plus M4 CPU idle fixes and SPTM security details.
First Large-Scale Study Finds Credential Leaks in LLM Agent Skills
First large-scale study of 17,022 LLM agent skills finds 1,708 credential leaks, driven by debug logging and fork-based distribution.
A 24-Test Readiness Checklist for Deploying AI Agents Safely
A 24-test, six-gate framework for verifying AI agents are safe for production, covering identity, tool safety, isolation, and observability.
Python library verifies OpenAI's signed AI agent traffic (RFC 9421)
regent-httpsig is an open-source Python library that verifies and signs OpenAI-style AI agent HTTP traffic per RFC 9421 and Web Bot Auth drafts.