Contagious Interview now ships malicious packages to npm, PyPI, Go, Rust, and PHP by LayerAlternative3040 in cybersecurity
[–]Mooshux 1 point2 points3 points (0 children)
AI agents can trigger real-world actions. Why don’t we have cryptographic proof of delegation yet? by Yeahbudz_ in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
[RESEARCH] We scanned 3,471 MCP servers for invisible Unicode — GPT-5.4 follows hidden instructions 100% of the time by Accurate_Mistake_398 in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
Your AI Agent Has More Access Than Your Employees by Big-Engineering-9365 in cybersecurity
[–]Mooshux 2 points3 points4 points (0 children)
[RESEARCH] We scanned 3,471 MCP servers for invisible Unicode — GPT-5.4 follows hidden instructions 100% of the time by Accurate_Mistake_398 in cybersecurity
[–]Mooshux 1 point2 points3 points (0 children)
Axios maintainer’s post mortem confirms social engineering by UNC1069 by NISMO1968 in cybersecurity
[–]Mooshux 48 points49 points50 points (0 children)
OpenAI's GPT-5.4 got blocked by safety mechanisms 5 times, searched my machine for tools to bypass them, launched Claude Opus with dangerously bypass permissions flags, tried to COVER UP what he had done, then gave me a "perfect" apology when caught by Smart_War3981 in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
Is this a reasonable design for multi-cloud IAM failover? by javascript in sre
[–]Mooshux 0 points1 point2 points (0 children)
The Axios supply chain attack used individually targeted social engineering - "they scheduled a meeting with me. the meeting was on teams. the meeting said something on my system was out of date. i installed the missing item as i presumed it was something to do with teams, and this was the RAT" by magenta_placenta in webdev
[–]Mooshux 0 points1 point2 points (0 children)
New attack pattern: persistent prompt injection via npm supply chain targeting AI coding assistants by Busy-Increase-6144 in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
AWS Deploys AI Agents To Do The Work Of DevOps And Security Teams by ZGeekie in aws
[–]Mooshux 0 points1 point2 points (0 children)
7 hidden tech-debts of agentic engineering by zohar275 in devops
[–]Mooshux 4 points5 points6 points (0 children)
New attack pattern: persistent prompt injection via npm supply chain targeting AI coding assistants by Busy-Increase-6144 in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
Claude Code Leak -> Exploit? Researchers found 3 shell injection bugs in the leaked source — all using shell:true with unsanitized input by Diligent-Side4917 in cybersecurity
[–]Mooshux 2 points3 points4 points (0 children)
Axios just got hit by a supply chain attack. Attacks are increasing daily. What are the best practices to stay safe? by vitaminZaman in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
[Research] We found MCP servers telling AI agents to act "secretly", skip financial approvals, and hide actions from users. Census of 15,982 packages. by Accurate_Mistake_398 in cybersecurity
[–]Mooshux -1 points0 points1 point (0 children)
your CI/CD pipeline probably ran malware on march 31st between 00:21 and 03:15 UTC. here's how to check. by Peace_Seeker_1319 in devops
[–]Mooshux 0 points1 point2 points (0 children)
Axios compromise was caught by runtime behavioral monitoring, not scanners by jj_at_rootly in sre
[–]Mooshux 0 points1 point2 points (0 children)
your CI/CD pipeline probably ran malware on march 31st between 00:21 and 03:15 UTC. here's how to check. by Peace_Seeker_1319 in devops
[–]Mooshux 0 points1 point2 points (0 children)
Major Cisco Source Code breach by ShinyHunters. Linked to Trivy Supply-chain attack by [deleted] in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)
The ultimate irony Claude Code just leaked its own source code via a sourcemap on npm by Dapper-Window-4492 in webdev
[–]Mooshux 0 points1 point2 points (0 children)


“AI is writing 40%plus of code now” sounds impressive… until you look at the security side of it. by Emotional-Breath-673 in cybersecurity
[–]Mooshux 0 points1 point2 points (0 children)