AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Browser AI agent security research: security researcher Gal Weizman of Forever Security demonstrated that one ordinary browser extension can hijack AI agents in Chrome, Edge, Perplexity Comet, Opera ...
Read the latest updates about Search results for litellm npm on The Hacker News cybersecurity and information technology ...
Discover how a covert WordPress malware exploits the Essential plugin and hides Ethereum Ether to maintain undetected ...
Discover how a new WordPress malware uses hidden plugins and blockchain command control to evade detection and compromise ...
A new npm supply chain campaign is hiding malware inside ordinary JavaScript package code instead of using the usual ...
Malicious npm package indexed-btree impersonated sorted-btree, using nearly 2M weekly downloads to steal data and deliver payloads.
WordPress malware hides as a must-use plugin and uses blockchain C2 to steal data and persist on compromised sites.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results