Rogue by Design: How a Sandboxed Pre-Release Model Jailbroke Itself and Hacked Hugging Face to Cheat an Exam
PointBlank: a fully-featured Python RAT that ran its command channel through a free note-hosting service
Attacks Analysis Slopsquatting Attacks: How an AI Mistake Became a New Way Into Your Software Supply Chain July 10, 2026
Attacks Analysis GhostTracker: an npm trojan that rebranded within hours of takedown — and kept the same C2 July 6, 2026
Attacks Analysis SkillLeak: A Browser-Credential Decryptor Delivered Through an MCP Skill July 3, 2026
Must Read Keys to use AI cybersecurity, Zero Trust SDLC, how to secure AI-generated code, AI Security July 2, 2026
Must Read What Is an AI Inventory? A Practical Guide to AI Asset Discovery, AI-BOM and Shadow AI July 1, 2026
Attacks Analysis DeviceDoor: a public npm package shipping a Microsoft 365 device-code phishing and bulk-mail framework June 30, 2026
Must Read OWASP Global AppSec EU 2026 Vienna: Key Takeaways on Secure Software Supply Chain, MCP Security, and the AI-BOM June 30, 2026
Attacks Analysis CryptoDAO Confusion: eleven npm packages, one payload, harvesting CI/CD and crypto-wallet secrets June 22, 2026
Attacks Analysis Permission Slip: An npm “Authorized Research” Cover Story Hiding Cloud-Metadata Probes and SYSTEM Persistence June 22, 2026