Dead drops in public: What the AI agent stashed on Hugging Face
A technical breakdown of artifacts the agent left in public repositories during the July 2026 Hugging Face intrusion.
20 articles
A technical breakdown of artifacts the agent left in public repositories during the July 2026 Hugging Face intrusion.
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A...
Mythos 5 was highlighted as being especially prone to believing the real world was a simulation.
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control.
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks ...
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours...
Enterprise AI has entered a different phase in 2026. The challenge is no longer simply giving developers access to an LLM API.
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and de...
Here's why CISOs must include Ai in the company's GRC program.
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including...
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Expl...
There are four kinds of AI agents, and each must be handled differently, Ping executives said.
Coding agents expand application risk beyond AI models to the tools, context and systems around them.
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mas...
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber offici...
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted wor...
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines c...
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor S...