OpenAI Agent Hacked Hugging Face—and Went Unnoticed for Days
An OpenAI evaluation agent reached Hugging Face production while pursuing benchmark answers.…
Grok Build Repository Upload: What to Do After Version 0.2.93
Grok Build 0.2.93 was observed uploading tracked repositories and Git history. Here…
Antigravity language_server.exe Malware Warning: Safe to Restore?
Antigravity 2.3.1 language_server.exe hash verified. Check the source, path, version, SHA-256, and…
AI Flower Seed Scams: Fake Plants, Real Payments, and Marketplace Red Flags
A visual investigation into AI-generated fake flower seed listings, marketplace red flags,…
Five Eyes AI Risk Checklist
Five Eyes warns that AI is shrinking patch windows. Use this practical…
Flowise Chatflow RCE
Flowise CVE-2026-40933 can turn a malicious chatflow import into server-side command execution.…
TrapDoor Hits npm, PyPI and Crates.io With AI Config Poisoning
TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets,…
ChromaDB CVE-2026-45829 Allows Pre-Auth Server Takeover
HiddenLayer disclosed ChromaToast, a pre-auth RCE in ChromaDB Python FastAPI server deployments…
Anthropic Mythos Helped Build a macOS M5 Kernel Exploit
Calif says researchers used Anthropic’s Mythos Preview to build a local macOS…
Fake Claude Code Ads Push MacSync Stealer on macOS
A Google Ads malvertising campaign used fake Claude Code install pages and…
Ollama CVE-2026-7482 Can Leak Prompts and API Keys
Cyera disclosed Bleeding Llama, an Ollama memory-leak flaw that can expose prompts,…
Fake OpenAI Hugging Face Repo: Infostealer Warning
HiddenLayer says a fake OpenAI-themed Hugging Face repository copied a privacy-filter model…
