Incident ResponseCISA shares postmortem of GitHub credential leakLaura FrenchJuly 10, 2026CISA credentials and code were uploaded to a public repository on a contractor’s personal GitHub account in May.
Ransomware‘GodDamn’ ransomware deploys PoisonX driver to kill EDRLaura FrenchJuly 10, 2026GodDamn, a rebrand of Beast and Monster ransomware, leverages AnyDesk for remote access.
AI/ML‘GhostApproval’ technique leads AI coding tools to alter files outside of sandboxLaura FrenchJuly 9, 2026The technique abuses symlinks to escape the intended workspace and weaken human-in-the-loop protections.
AI/ML‘GitLost’ prompt injection leaks private repos via GitHub Agentic WorkflowsLaura FrenchJuly 8, 2026An issue opened on a public repository can lead the agent to disclose private details.
AI/MLMalicious websites trick AI agents into crypto payments, context poisoningLaura FrenchJuly 7, 2026Indirect prompt injections hidden in HTML were discovered on sites targeting developers and cryptocurrency owners.
Ransomware1st ‘agentic ransomware’ JADEPUFFER invades database at machine speedLaura FrenchJuly 2, 2026The LLM fixed a failed login attempt within 31 seconds, demonstrating real-time adaptability.
Ransomware‘Interpol’ emails spread custom ransomware with decryption key left insideLaura FrenchJuly 2, 2026The campaign targets small businesses with fearmongering emails.
AI/ML‘BioShocking’ jailbreak tricks AI browsers into disclosing private dataLaura FrenchJuly 1, 2026A website framed as a game led AI assistants to submit private GitHub file contents.
MalwareAttack exploiting SimpleHelp vulnerability deploys novel loader, infostealerLaura FrenchJune 30, 2026The TaskWeaver loader delivers Djinn Stealer, which targets dev credentials and AI tokens.
Vulnerability Management2 Linux kernel flaw PoCs published, enabling local privilege escalationLaura FrenchJune 26, 2026One of the flaws, DirtyClone, is a variant of the DirtyFrag vulnerability class.