On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privileges to potentially ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
AI agent tool bypass vulnerability CoreBreak exposed production agent infrastructure at AWS, Google, and Vercel, where attackers could invoke tools without any model turn. AWS fixed its managed ...
AI agent flaws in AWS, Google, and Vercel let forged tool calls reach tools without model authorization, while several paths ...
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning ...
CISA warns that three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat have been exploited in the ...
A roundup of the latest noteworthy AI-assisted attacks, threats, risks, and vulnerabilities, and what they portend for cyber defense.
Last month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with ...
Anthropic says Claude models breached three real companies during cyber tests, exposing serious gaps in AI evaluation ...