According to new research from Blackpoint Cyber's Adversary Pursuit Group (APG), published on July 30, the intrusion hit two ...
Three Hugging Face Diffusers flaws bypass trust_remote_code, letting crafted model repositories execute code during custom ...
LiteLLM supply chain attack exposed stolen credentials at 2,488 corporate firms in March 2026; security researcher Kevin ...
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
VS Code model picker now allows users to switch between Anthropic and Copilot providers between turns reconfiguring the agent host. Microsoft has released Visual Studio Code 1.133, an update to its ...
Because 'trust me' isn't a permission model for your AI coding agent.
Vulnerabilities can lurk within production code for years or decades — and AI tools have opened a gateway to a glut of new long-hidden discoveries.
LiteLLM supply chain attack exposed 2,500+ companies and 434,000 CI/CD pipelines in 40 minutes. FBI warns threat still live.
Threat-intelligence firm CloudSEK said in a report published August 11, 2026 that it has identified more than 2,500 organizations potentially exposed by the March 2026 supply-chain compromise of ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
A roundup of the latest noteworthy AI-assisted attacks, threats, risks, and vulnerabilities, and what they portend for cyber defense.