Mandiant Report: AI Assistant Hijacked for Supply Chain Attack
A new Mandiant report details how an attacker hijacked an AI coding assistant to spread a worm across repositories, highlighting a new supply chain risk.
A new Mandiant report details how an attacker hijacked an AI coding assistant to spread a worm across repositories, highlighting a new supply chain risk.
Enterprise AI adoption is causing a 685% spike in security alerts, but most are noise, creating a new signal-to-noise problem for security teams.
A new 'GitSpawn' vulnerability allows malicious Git repositories to execute arbitrary code via AI coding agents, requiring immediate patches for tools like Claude Code and Cursor.
Active exploitation of critical vulnerabilities in Langflow and Ruby on Rails allows attackers to execute code and compromise AI development environments.
A new 'Cryptographic Context Injection' attack uses encrypted on-page data to trick xAI's Grok into exfiltrating user chat history.
Gemini 3.6 Flash's 17%-fewer-tokens claim only cuts your bill on output-heavy workloads. Here's how to run a real cost-per-task teardown before switching.
Hands-on with Microsoft's MDASH bug hunter in public preview: what it caught, the logic bugs it missed, and whether the 622-patch headline survives a real repo.