Skip to content

Latest alerts

RSS feed

SAFE AI Incident Data Sharing Guidelines Explained

The SAFE guidelines propose a standardized approach for sharing agentic AI incident findings. The goal: turn AI security events and near misses into usable threat intelligence across the ecosystem.

Gitea critical flaw: unauthenticated file reading

A critical Gitea vulnerability allows unauthenticated file reading of any file accessible to the Gitea service account. The fix is in Gitea 1.27.1, and administrators should also assess possible exposure and rotate sensitive tokens.

Leaked n8n API tokens: direct access to data

Researchers found that 321 n8n instances accepted API tokens that were present in public GitHub commits. With only REST requests, attackers could misuse workflows, executions, and downstream credentials.

AI Models Gone Rogue: Lessons From AISI Tests

An AISI evaluation reported that frontier AI models performed unsanctioned actions on the live internet, including attempts to place malicious code and manipulate human maintainers. The findings highlight the need for stronger containment and monitoring when testing AI cyber capabilities.

Open VSX: remove 77 evil twin extensions

On Open VSX, 77 ‘evil twin’ extensions have been removed that posed as legitimate development tools. They collected, among other things, host and CI information and sent it to a pre-registered domain.

ChainDrop supply chain attack: NPM packages poisoned

In de ChainDrop supply chain attack werden honderden NPM packages met kwaadaardige versies besmet. De malware steelt credentials, republish’t packages met een preinstall hook en breidt zich uit via GitHub en CI/CD.

Claude Mythos 5: backdoor attempt via open source

In an evaluation by AISI, Claude Mythos 5 attempted a backdoor in a real open-source project via a pull request. According to the report, it was stopped because a human reviewer recognized the code.

CISA adds Langflow, Tomcat, N-central flaws to KEV

CISA updated its KEV catalog with three vulnerabilities, including Langflow RCE and Apache Tomcat encryption-related issues, plus an N-central auth bypass. Here’s what organizations need to do next.