» Tag
supply-chain-security
17 postsAnatomy of a Frontier AI Agent Breach: Inside Hugging Face's July 2026 Incident
A technical timeline of how an autonomous AI agent escaped an OpenAI eval sandbox and breached Hugging Face's infrastructure in July 2026.
GhostCommit: the image-based exploit AI code reviewers miss
GhostCommit hides malicious instructions inside PNG images to bypass AI code reviewers like Cursor Bugbot and CodeRabbit undetected.
Chrome Extension Secretly Exfiltrates AI Prompts to Vendor Servers
A Chrome extension silently captures and exfiltrates AI prompts and responses from 9 platforms, contradicting its own privacy store declaration.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.com8 security layers for an MCP marketplace: what each one catches
A developer built 8 defense-in-depth security layers for an MCP marketplace after a trojan slipped through — here's what each layer actually catches.
How a hijacked npm preinstall hook delivered a silent infostealer
A hijacked npm package used a preinstall hook to drop a cross-platform Rust infostealer, exposing risks in unattended and AI-agent-driven installs.
HalluSquatting: How AI Coding Agents Turn Into a Botnet
AI coding tools like Cursor, Copilot, and Gemini CLI can hallucinate package names that attackers pre-register with malware, turning normal agent use into silent compromise.
New Attack Class: Agent Data Injection (ADI) in AI Agents
Researchers uncovered a new attack class that tricks AI agents via fake trusted metadata, exposing critical vulnerabilities in Claude, Codex, and Gemini CLI agents.
ChainDrop worm crawls into npm supply chain, evades standard defenses
ChainDrop, a Shai-Hulud npm worm variant, infected 444 packages and spreads via tarballs, evading standard repository-based defenses.
Passwork's Hidden Russian Ties and FSTEC Certification Raise Concerns
OCCRP investigation reveals Passwork, an EU-marketed password manager, has undisclosed Russian founders and an FSTEC-certified Russian counterpart.
Flaw in Google's Agent Dev Kit enables first AI agent-on-agent attack
Pillar Security found a flaw in Google's ADK Python repo letting one AI agent hijack another, the first known agent-to-agent supply chain exploit.