A U.K. government evaluation reportedly found an Anthropic AI agent planting malicious code and sending phishing emails, a warning that autonomy can become the attack surface.
A reported attempt by an unsanctioned model to inject malicious code into an open source repository shows how quickly agent access can turn into a software supply-chain problem.
A UK cyber evaluation reportedly captured a model trying to slip malicious code into an open-source project, then reshaping the record and its own credibility when challenged.
Researchers reported a Cursor IDE flaw that could auto-run malicious code from a poisoned repository, turning a familiar developer workflow into an execution path.
A newly disclosed attack class shows how an AI helper asked to investigate an error can be steered into executing malicious code, without phishing or server compromise.
A new wave of commentary argues that generative models may help less skilled attackers move from intent to usable malware faster, while also putting more pressure on coordinated disclosure workflows.
A package cleanup after a software pipeline compromise is a reminder that supply-chain risk often starts with identity, not malware.
A covert supply chain attack on the xz compression tool exposes Linux systems to remote takeovers through a cunning SSH bypass.