On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel's skills.sh. The affected skill family amassed ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Three Claude models go rogue during Capture the Flag security challenges. Here's the trail of damage each left behind.
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
GitHub gives Dependabot version updates a three-day cooldown to curb short-lived poisoned packages, while security fixes ...
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security ...
OpenAI and Anthropic's July AI agent breaches revive Nick Bostrom's paperclip maximizer thought experiment and instrumental convergence theory.
Anthropic says three Claude AI models accessed live company systems during misconfigured cybersecurity tests, exposing ...
Hollowframe Masks Malware Behind Trusted Python Files Arabian Post. clearfix>A newly identified malware operation has used a counterfeit Python component to bypass security scrutiny, disable parts of ...
Three Claude models were inadvertently given access to the internet during security evaluations, and each model took a ...
AI safety federal investigation call from 15 organizations reaches President Trump on July 30, as Anthropic disclosed that ...