Uber Open-Sources ADR to Secure AI Coding Agents
Uber open-sourced ADR, a production-tested security system that monitors AI coding agents like Claude Code, Cursor, and Codex for risky behavior.
Uber open-sourced ADR, a production-tested security system that monitors AI coding agents like Claude Code, Cursor, and Codex for risky behavior.
A study of 40,000+ sessions found humans miss about one in three threats when approving AI coding agent commands. Here is why the human-in-the-loop leaks.
On July 20, 2026, Pillar Security showed that Codex CLI, Cursor, and Gemini CLI sandboxes can be escaped through a mounted Docker socket, with no kernel exploit and nothing logged.
Hugging Face disclosed a July 2026 breach carried out by an autonomous AI agent that ran 17,000+ actions from a single malicious dataset. Here is what was hit, what was safe, and how to secure your account.
A Claude web fetch flaw leaked a user's memory data to an attacker with no malware and no clicks. Here is how the lethal trifecta works and how to defend the agents you build.
A security researcher has shown that xAI's Grok Build CLI was uploading entire git repositories, including unredacted secrets, to a Google Cloud Storage bucket, and that the tool's own opt-out toggle did not stop it.
Hackers seized high-profile Instagram accounts by exploiting Meta AI customer support, asking the bot to link a new email without verification. Victims include Obama White House account and Sephora.
A DPRK-linked supply chain attack plants a RAT via npm packages and routes all stolen credentials to private HuggingFace datasets. Two AI developer victims confirmed May 28 2026.
PromptArmor disclosed that Microsoft Copilot Cowork can be tricked into exfiltrating files from a user's tenant through a chained prompt-injection attack on SharePoint.
Anthropic reported that Mythos Preview found over 10,000 critical software bugs through automated security analysis.
Perplexity open-sourced Bumblebee, a read-only supply-chain scanner for macOS and Linux that detects compromised packages.
GitHub confirmed unauthorized access to its own internal repositories on May 19, 2026. Customer repos are not known to be affected, but here is what AI creators should audit now.
A May 19 npm supply-chain wave compromised 317 packages including timeago.js and the @antv ecosystem, rewriting .claude/settings.json to hijack Claude Code, Codex, and Cursor sessions.
A new $9.99 macOS app scans the local chat databases of Claude Code, Cursor, and VS Code Copilot for exposed API keys and secrets before they cause damage.
Security researchers have found a way to hijack voice AI models using inaudible sounds embedded in ordinary audio clips. AudioHijack achieved 79 to 96 percent success rates across 13 large audio language models.
Security firm Calif used Anthropic's Mythos Preview to build the first macOS M5 kernel exploit in five days, bypassing Apple's Memory Integrity Enforcement.
mistralai==2.4.6 was backdoored in the Mini Shai-Hulud supply chain attack. PyPI quarantined the project. Here is what to check and do if you build with Mistral's Python SDK.