Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
Given enough leeway, an AI system can cause real damage entirely on its own, with no malicious intent and no...
Given enough leeway, an AI system can cause real damage entirely on its own, with no malicious intent and no...
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI)...
A security flaw in Anthropic’s Claude for Chrome could allow a malicious browser extension to trigger Gmail, Google Docs, and...
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install...
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that...
Your Chrome searches may not have been going where you thought. Microsoft has uncovered a malicious Chrome extension masquerading as...
Swati KhandelwalJun 29, 2026Browser Security / Web Security Microsoft has found a malicious Chrome extension that posed as the AI...
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary...
Swati KhandelwalJun 26, 2026AI Security / Vulnerability A high-severity flaw in Amazon Q Developer let a malicious repository run commands...
A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and...
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a...
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of...
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the...
Cybersecurity researchers are sounding the alarm about what has been described as "malicious activity" in newly published versions of node-ipc....
Ravie LakshmananMay 11, 2026Supply Chain Attack / Threat Intelligence A malicious Hugging Face repository managed to take a spot in...