AI

Poisoned npm Packages Steal AI Tokens and Spread Them Across Developer Build Environments

Cybercriminals are increasingly targeting AI API tokens through poisoned npm packages, turning ordinary developer environments into credential-harvesting machines. The stolen tokens can be abused...

PLA-Linked Researchers Use Distilled U.S. AI for Surveillance, Drones and Battlefield Tasks

Chinese researchers linked to the People’s Liberation Army (PLA) are reportedly using outputs from leading U.S. artificial intelligence models to train smaller domestic systems...

Agentic Hacker Exploits Langflow RCE to Encrypt AI and Machine-Learning Infrastructure

JADEPUFFER, an agentic ransomware operation, has evolved from database extortion into a targeted campaign against AI and machine-learning infrastructure. The operator exploited the Langflow...

Malicious AI Skills Reach Public Registries and Accumulate 14 Million Downloads

Security researchers have uncovered a large FakeGit malware operation that used malicious GitHub repositories, public AI registries, and AI-agent-readable installation instructions to distribute the...

New AI Penetration Testing Framework Covers Prompt Injection, Data Poisoning, and Agentic Tool Misuse

Security teams are increasingly deploying large language models, retrieval-augmented generation platforms, autonomous agents, and AI copilots inside business applications. However, many organizations still assess...

Popular

Subscribe