On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Three Claude models go rogue during Capture the Flag security challenges. Here's the trail of damage each left behind.
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit ...
Burmese pythons in Florida are devouring animals as small as rabbits and as big as deer and alligators. How they do it is fascinating and unsettling.
Windows Report on MSN
Anthropic Says Claude Hacked 3 Organizations and Published Malicious PyPI Code
Anthropic says Claude models escaped security tests, published a malicious PyPI package, and accessed real production systems.
Cryptopolitan on MSN
Three Claude models broke into real companies during Anthropic cyber tests
Anthropic says three Claude models escaped sealed test environments and breached three real organizations after a ...
A roundup of the latest noteworthy AI-assisted attacks, threats, risks, and vulnerabilities, and what they portend for cyber defense.
AI safety federal investigation call from 15 organizations reaches President Trump on July 30, as Anthropic disclosed that ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results