Advertisement
Chrome Gemini Live Hijacking: Malicious Extension Vulnerability
A vulnerability in Google Chrome’s Gemini Live AI assistant allowed malicious extensions to hijack sessions and steal user files. Learn more about the impact.
LLM-Assisted Deanonymization: Scaling Automated Identity Discovery
New research highlights how LLM agents automate the deanonymization of anonymous online posts across Reddit and Hacker News with high precision and scale.
ClawJacked Vulnerability in OpenClaw AI Agent Enables Data Hijacking
Analysis of the ClawJacked attack where malicious websites can hijack local OpenClaw instances to steal sensitive LLM API keys and private conversation data.
ClawJacked: Hijacking Local OpenClaw AI Agents via WebSocket
A high-severity vulnerability in the OpenClaw AI gateway allows malicious websites to take control of local AI agents by exploiting WebSocket flaws.
Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies
All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.
Claude Code Security Analysis: Assessing AI CLI Assistant Risks
Technical analysis of Anthropic's Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.
Advertisement
AI Code Generation Poses Supply Chain Risk to Developer Machines
Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…
Data Poisoning Risks in Real-Time AI Search and Ingestion
A recent experiment highlights how rapid web scraping for AI models like Gemini and ChatGPT enables data poisoning attacks through unverified web content.
Mitigating Identity Risks in Autonomous AI Agent Workflows
Enterprise security must evolve to manage AI agents as non-human identities (NHIs) by implementing intent-based controls and solving over-scoped privilege risks.
AI-Driven Package Hallucination: A New Frontier in Supply Chain Exploitation
Analysis of a novel attack vector where autonomous AI agents facilitate malicious package injection through dependency confusion and LLM hallucinations.
Technical Analysis: Multi-Vector Threats Spanning Web Skimming, AI Prompt Injection, and Volumetric DDoS
A deep dive into redundant Magecart exfiltration techniques, PromptSpy AI exploitation frameworks, and the escalation of 30Tbps volumetric DDoS attacks.
Securing AI Infrastructure: Mitigation Strategies for Lifecycle Vulnerabilities
An assessment of architectural risks in AI deployments, emphasizing infrastructure-level threats and model supply chain vulnerabilities over application-layer prompt…
Logic Flaws and Data Exfiltration in Autonomous AI Agent Architectures
Technical analysis of guardrail bypasses in LLM-integrated agents, highlighting the transition from conversational models to autonomous actors with privileged access.