groundy

security

  1. jun 05securityOpenAI Adds Lockdown Mode to ChatGPT, Shifting Prompt-Injection Risk to Users
  2. jun 05securityActivation Steering Was Sold as LLM Control. New Work Makes It an Attack Surface
  3. jun 05securityCatching LLM Agents Leaking Credentials From Their Own Activations
  4. jun 05securityThe 2026 npm Attacks Proved AI Coding Assistants Are a Supply-Chain Target
  5. jun 04securityChatGPT's New Lockdown Mode Borrows Apple's Name for a Prompt-Injection Kill Switch
  6. jun 04securityStudents Are Prompt-Injecting AI Graders to Score Full Marks
  7. jun 04securityRemoving an LLM Backdoor Post-Training Without the Poisoned Data
  8. jun 04securityStored Prompt Injection Now Persists Across AI Agent Sessions
  9. jun 04securityLLM Data Poisoning Survives the Data-Cleaning Defenses Built to Stop It
  10. jun 03securityWhy OpenAI Bets on Instruction Hierarchy to Stop Prompt Injection
  11. jun 03securityStopping Multi-Turn LLM Jailbreaks Without Retraining the Model
  12. jun 03securityAfrican Languages Are a Jailbreak Blind Spot for English-Tuned LLM Safety
  13. jun 03securityPoisoning Open-Source LLM Merges: One Bad Checkpoint Hijacks the Result
  14. jun 03securityAn Autonomous Research Agent Now Discovers SOTA LLM Jailbreak Attacks
  15. jun 03securityMalware Can Prompt-Inject the AI Agent Reverse-Engineering It
  16. jun 03securityCVE-Factory Turns Published CVEs Into Security Agent Training Data. A 32B Model Beats Claude 4.5 Sonnet.
  17. jun 02securityLLM Reasoning Traces Leak the Private Data They're Told to Hide
  18. jun 02securityVideo Jailbreaks Hit Multimodal LLMs by Splitting Payloads Across Clips
  19. jun 01securityVercel AI SDK CVE-2025-48985: Input Validation Bypass Hits LLM App Builders
  20. jun 01securityHijacking AI Agent Memory: One Conversation Can Plant a Persistent Trojan
  21. jun 01securityWhy Attack Success Rate Misleads LLM Jailbreak Benchmarks
  22. may 31securityJob Seekers Are Prompt-Injecting AI Resume Screeners. New Study Measures the Hit Rate
  23. may 31securityWhy Audio Jailbreaks Slip Past the Safety Training Built for Text LLMs
  24. may 31securityLoRA Adapter Backdoors Generalize Beyond Their Trigger Tokens
  25. may 29securityThree Labs Concede Browser Agents Cannot Stop Prompt Injection
  26. may 29securityVercel Firewall Now Blocks SAMLStorm. Can an Edge WAF Fix a SAML Signature Flaw?
  27. may 27securityVercel Could Block React2Shell at the Edge. Its Next 13 CVEs Had No Shortcut.
  28. may 27securityOpenAI Adds a GPT-5 System Card Addendum on Sensitive Conversations
  29. may 27securityMCP Tool Description Poisoning: New Benchmark Shows Agents Trust Manuals That Lie
  30. may 27securityOpenAI's New Safety Bug Bounty Pays Researchers for Jailbreaks and Policy Bypasses
  31. may 27securityAxios npm Compromise Forces Vercel Into Platform-Level Remediation
  32. may 27securityNext.js Dev Server CVE-2025-48068: Any Web Page Could Read Your Source Files
  33. may 26securityApple Names Claude in CVE Credit Line, Setting Vendor Attribution Precedent
  34. may 25securityCISA's Internal Data Leak Tests the Disclosure Standards It Sets for Others
  35. may 25securityTanStack npm Attack: When OIDC Trusted Publishing Becomes the Attack Vector
  36. may 25securityNx s1ngularity Attackers Used Local Claude Code and Gemini CLI to Steal Developer Tokens
  37. may 24securityOpenAI Ships Lockdown Mode and Elevated Risk Labels for ChatGPT Sessions
  38. may 23securityAI Jailbreaks Are Now a Reasoning Problem, Not a Prompt Problem
  39. may 23securityJailbreak Defense Now Lives in Model Weights, Not in Prompt Filters
  40. may 23securityVercel Blocks Deploys With Vulnerable next-mdx-remote by Default: Platform Mitigation Outpaces the CVE Cycle
  41. may 23securityVercel's Next.js Middleware Bypass Postmortem: What the Fix Reveals About Edge Runtime Auth
  42. may 23securityOpenAI's New Agent Defense Post Concedes Prompt Injection Is Architectural, Not Patchable
  43. may 23securityWhen Stronger Backdoor Triggers Backfire: An arXiv Theory Paper Inverts a Core Defense Assumption
  44. may 18securityDPrivBench: LLMs Score 99.5% on Textbook DP but Collapse on Advanced Reasoning
  45. may 18securityCatching Graph Neural Net Backdoors by Influence, Not Pattern
  46. may 18securityTrustFall: One Keypress in Claude Code, Gemini CLI, Cursor, and Copilot CLI Triggers Unsandboxed RCE
  47. may 18securityMini Shai-Hulud Ships the First Malicious npm With Valid SLSA Provenance
  48. may 18securityMultiBreak Benchmark: 10,389 Multi-Turn Jailbreak Prompts Raise ASR 54pp on DeepSeek-R1-7B
  49. may 18securityNext.js CVE-2026-44578: WebSocket Upgrade SSRF Hits 79,000 Self-Hosted Instances From 13.4.13 Onward
  50. may 18securityPraisonAI CVE-2026-44338: Legacy Flask API Ships With AUTH_ENABLED=False, First Scan in 3h44m