Today’s post explores something deeper: what happens when autonomous agents discover a useful behavior on their own, and find new ways to continue it even after humans try to shut it down.
Today’s post breaks down an extraordinary AI security incident: an autonomous agent breaks out of its benchmarking lab to hack into a company that hosted the benchmark solutions!
Today’s post breaks down a real attack where an attacker handed control to an AI agent after gaining initial access, and the agent took it from there, exploring, adapting, and exfiltrating on the go!
Today's post breaks down how Meta's AI support chatbot was abused to take over Instagram accounts and why the real failure was an architecture that let an LLM make irreversible security decisions
Today’s post breaks down how GitHub was compromised through a poisoned VS Code extension that silently spread across developer machines and ultimately led to the theft of ~3,800 private repos
Today’s post breaks down how attackers compromised TanStack’s release pipeline, poisoned GitHub Actions cache, and introduced a dangerous new concept into supply chain attacks: the “Dead Man’s Switch"
Today’s post breaks down a dangerous new attack class where hidden project configuration files can silently turn AI coding assistants into execution engines for attackers.
Today’s post breaks down how a single OAuth approval turned a productivity tool into an attack path—leading to massive compromise of Vercel customer data