groundy

security

  1. Vercel's Flags SDK Exposed Feature-Flag Definitions via CVE-2025-46332
  2. Jailbreak Suffixes Hit Harder at Specific Token Positions, New GCG Variant Shows
  3. Activation Steering Was Sold as LLM Control. New Work Makes It an Attack Surface
  4. The 2026 npm Attacks Proved AI Coding Assistants Are a Supply-Chain Target
  5. ChatGPT's New Lockdown Mode Borrows Apple's Name for a Prompt-Injection Kill Switch
  6. Stored Prompt Injection Now Persists Across AI Agent Sessions
  7. LLM Data Poisoning Survives the Data-Cleaning Defenses Built to Stop It
  8. Why Attack Success Rate Misleads LLM Jailbreak Benchmarks
  9. OpenAI's New Safety Bug Bounty Pays Researchers for Jailbreaks and Policy Bypasses
  10. AI Jailbreaks Are Now a Reasoning Problem, Not a Prompt Problem
  11. TrustFall: One Keypress in Claude Code, Gemini CLI, Cursor, and Copilot CLI Triggers Unsandboxed RCE
  12. MultiBreak Benchmark: 10,389 Multi-Turn Jailbreak Prompts Raise ASR 54pp on DeepSeek-R1-7B
  13. InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE
  14. Mercor's 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets
  15. Citizen Lab's 'Bad Connection' Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7
  16. March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks
  17. The Mysterious Case of Chinese Bot Traffic in 2026: How AI-Powered Bots Are Rewriting the Rules of Detection