security
security
archive
- Vercel's Flags SDK Exposed Feature-Flag Definitions via CVE-2025-46332
- Jailbreak Suffixes Hit Harder at Specific Token Positions, New GCG Variant Shows
- Activation Steering Was Sold as LLM Control. New Work Makes It an Attack Surface
- The 2026 npm Attacks Proved AI Coding Assistants Are a Supply-Chain Target
- ChatGPT's New Lockdown Mode Borrows Apple's Name for a Prompt-Injection Kill Switch
- Stored Prompt Injection Now Persists Across AI Agent Sessions
- LLM Data Poisoning Survives the Data-Cleaning Defenses Built to Stop It
- Why Attack Success Rate Misleads LLM Jailbreak Benchmarks
- OpenAI's New Safety Bug Bounty Pays Researchers for Jailbreaks and Policy Bypasses
- AI Jailbreaks Are Now a Reasoning Problem, Not a Prompt Problem
- TrustFall: One Keypress in Claude Code, Gemini CLI, Cursor, and Copilot CLI Triggers Unsandboxed RCE
- MultiBreak Benchmark: 10,389 Multi-Turn Jailbreak Prompts Raise ASR 54pp on DeepSeek-R1-7B
- InstructLab CVE-2026-6859: Hardcoded trust_remote_code=True Turns Any HuggingFace Model Into RCE
- Mercor's 4TB Lapsus$ Breach Hands Voice-Clone Attackers 40,000 Pre-Verified Targets
- Citizen Lab's 'Bad Connection' Names Three Telecom Entry Points, Shows Diameter Silently Falls Back to SS7
- March-April MCP CVEs Expose the Local-Host Trust Model in AI Agent Frameworks
- The Mysterious Case of Chinese Bot Traffic in 2026: How AI-Powered Bots Are Rewriting the Rules of Detection