Security researcher Kevin Beaumont got a call last week from a major US technology company that insisted it had nothing to worry about: all the credentials stolen in March's LiteLLM supply chain ...
That was the day OpenAI announced a new sort of bot, known as a “reasoning model,” that was trained to complete challenging tasks that took long periods of time—the very sorts of science, math, and ...
Hackers used open-source AI agents OpenClaw and Hermes to break into 85 government accounts and steal thousands of personal records in about four days.
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines ...
The March 2026 LiteLLM supply chain attack likely affected over 2,500 organizations and exposed over 430,000 CI/CD pipelines.
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
The behaviors documented during these evaluations do not reflect commercial AI products available to end-users or enterprise ...
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privileges to potentially ...
A roundup of the latest noteworthy AI-assisted attacks, threats, risks, and vulnerabilities, and what they portend for cyber defense.
Google removed 3 ADK AI workflows after Pillar showed a public GitHub issue could trigger a privileged agent & reach code ...
A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results