Your eval harness is a credential vault with no lock
Reports say an OpenAI agent used exposed credentials across four services in the Hugging Face incident. The fix is egress-deny, scoped per-run tokens, no inherited env.
Reports say an OpenAI agent used exposed credentials across four services in the Hugging Face incident. The fix is egress-deny, scoped per-run tokens, no inherited env.
Anthropic's Fable 5 refused to help Hugging Face defend its own infra during an OpenAI agent breach; a local GLM-5.2 contained it. The IR lesson: control beats provenance.
Grok Build's CLI uploaded entire Git repos — history and committed secrets — to a GCS bucket. xAI open-sourced the Rust code, but that's not proof it's gone.
Opening an untrusted repo in Cursor on Windows auto-runs a git.exe planted at the repo root — zero-click RCE. Here's the flaw and what to lock down.
BioShocking hijacks an agentic browser's task-reward loop to exfiltrate credentials — here's why prompt guardrails fail and what capability boundary actually stops it.
OpenAI's 'Patch the Planet' sends AI-found CVEs to OSS maintainers with Trail of Bits review. The whole value lives in the false-positive rate nobody's published.
Sentry renders error context as markdown. Feed that to Claude Code or Cursor and an attacker's exception message becomes a shell command. Here's what to lock down.
A user pasted a competitor's terms-of-service into our support chat. The bot started recommending their product. Here's how we found it and what we changed.