40 related articles

Anthropic's Claude generates nonexistent package names during coding assistance, which malicious actors register to steal real API keys. Analysis of the attack chain and developer defenses.

A security audit of 7.6PB of HuggingFace training data uncovered massive API key and credential leaks. Analysis of risks, scanning challenges, and data supply chain security governance.

Deep technical breakdown of an AI Agent-driven intrusion at a frontier AI lab, covering the full attack timeline from reconnaissance to data exfiltration, plus defense strategies.

Deep technical breakdown of an AI Agent-driven frontier lab intrusion, covering the full timeline from reconnaissance to data exfiltration, with analysis of growing offense-defense asymmetry.

Deep analysis of Hugging Face's frontier lab AI agent intrusion report, covering indirect prompt injection, lateral movement, data exfiltration, and defense-in-depth strategies for AI agent security.

GitHub upgrades supply chain defenses for npm and Actions with provenance attestation, least privilege enforcement, and anomaly detection to combat attacks.

GitHub upgrades supply chain defenses for npm and Actions with provenance attestation, least privilege principles, and anomaly detection across multiple layers.

Investigators traced Steam malware to its creator using Bitcoin transaction chains, Google Cookies, and Uber Eats orders—revealing how cross-referencing digital evidence destroys the illusion of online anonymity.

Chinese users can subscribe to ChatGPT Plus via Alipay without foreign credit cards. Complete guide covering the process, steps, precautions, and account security tips.

Subscribe to ChatGPT Plus via Alipay without a foreign credit card. Step-by-step guide covering payment flow, tips, security advice, and alternatives for users in China.

A U.S. citizen faces criminal charges after a GrapheneOS phone auto-wiped during an airport border search. Analysis of the privacy rights vs. law enforcement clash.

Videos promising 'free access to all global AI models' hide serious risks: fake version numbers, data leaks, and phishing scams. Here's what you need to know.

Are third-party ChatGPT top-up services really safe? This deep dive unpacks how they work, the ban risks, and financial dangers — plus the right way to subscribe officially.

A complete guide to modern authentication: Passkeys, Digital Credentials API, and FedCM — covering the full account lifecycle. Modern solutions deliver 2× faster sign-in and 4× higher success rates.

GPT-5.6 Soul Ultra claims to prove the 50-year-old Cycle Double Cover Conjecture in under an hour using 64 parallel agents. We examine the technical path, missing peer review, and formal verification gaps.
Ghostcommit Attack Explained: How Mali…
Ghostcommit is a new supply chain attack targeting AI coding tools that hides malicious instructions in PNG pixels, bypassing automated code review to steal .env secrets via indirect prompt injection.

A Bilibili video promoting 'free unlimited ChatGPT 5.6' is full of fake model names, stolen account pools, and phishing links. Here's a full breakdown of the scam.

Sysdig captured JadePuffer, the first fully autonomous LLM attack agent: exploited Langflow RCE, self-corrected in 31 seconds, laterally moved, encrypted databases, and left a ransom note — a deep-dive into weaponized AI agents.

Are third-party ChatGPT top-up services safe? We expose how ¥158 recharge scams work, the real risks of account theft and bans, and how to subscribe safely.

Cross-site prompt injection is becoming the trickiest security threat for Web agents. This article analyzes the Prismata project's 'confining defense' approach—controlling injection's blast radius via context isolation, permission boundaries, and trust grading.