Chrome Extension Returns with Malicious Intent After Removal
A Chrome extension removed for stealing AI chats returned to the Web Store and resumed malicious activities — immediate remediation recommended.
§Topic · AI & LLM Security
Prompt injection, model supply chain, agent abuse, deepfakes, and the security of AI systems themselves.
All dispatchesFlaws in Claude Code and Google's Gemini CLI let an unprivileged GitHub issue execute code on CI runners and expose secrets.
Varonis found a one-click RovoBlast vulnerability that could expose Confluence, Jira and SharePoint data to attackers.
SANS NewsBites flags exposed OT controllers after water attacks, Chinese telecoms' US presence, and OSAA's SAFE proposal for AI findings sharing.
Researcher demonstrated a PoC providing C2-style influence over ChatGPT's isolated sandbox, highlighting container escape risks.
Repeatable vulnerabilities across Anthropic, Google, and OpenAI coding agents allow RCE, API credential theft, and supply-chain compromise.
Get these articles delivered to your inbox.
Subscribe free