Attackers Target Agents via The Skill Supply Chain
An active malware campaign used typosquatted skills, trojanized packages, and remote loaders to target users of popular AI tools.
The two blog readers would know that it is comprised mostly of unfinished thoughts about breaking AI agents, hacking, cloud security, application security, citizen development and infosec.
An active malware campaign used typosquatted skills, trojanized packages, and remote loaders to target users of popular AI tools.
For six months we ran a global network of AI honeypots with exposed inference and agent endpoints. Attackers found them fast, exploiting days-old CVEs for RCE, stealing environment variables and API keys, and hijacking our infra to run offensive tooling against real victims. The twist: to abuse our tokens they had to hand over their prompts, tools, and reasoning, leaving the attacker's intent…
AI slop is creeping into Slack messages, emails, tickets, and docs, and it's hollowing out the human intent that makes communication valuable. Use AI to sharpen your thinking, but don't reduce yourself to a copy-paste operator. We want your taste, your deliberate choices.
An investigation into the Cline supply chain attack, revealing how a bug bounty hunter weaponized a public PoC via prompt injection to steal npm credentials.
Investigating the recent Cline CLI supply-chain compromise using the Raptor AI agent to conduct OSS forensics and uncover the root cause.
Security researchers have publicly confirmed, for the first time, that threat actors are actively scanning and probing enterprise AI systems for exploitation. Correlated observations from DefusedCyber and GrayNoise show systematic reconnaissance of exposed LLM endpoints—using techniques associated with known CVE exploitation pipelines—marking a shift from theoretical AI risk to active adversary…
Links and deck for my keynote at AI Agent Security Summit, SF Oct 8. There's a big discrepancy between our feeling of progress and reality for hackers. AI security and safety benchmarks go up. But hackers don't notice. Their partying like its 1999. Security from AI has been going in the wrong direction, relying on soft boundaries like AI guardrails and safety training. We CAN make progress though.…
How should we reason about machines taking over
Bottom lines, demos, slides, and attacker capabilities from the BlackHat USA 2025 talk
The attacker deletes their user. Luckily we still have GH Archive.