On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
Three Hugging Face Diffusers flaws bypass trust_remote_code, letting crafted model repositories execute code during custom ...
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
Amazon Web Services Inc. today launched Kiro Crew, an autonomous workspace that keeps artificial intelligence coding agents ...
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
Las Vegas was hotter than hell last week, but not as hot as the market for artificial intelligence-enabled security at Black ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
A local model finally finished the job without me arguing with it.
At Black Hat USA, Zenity Labs today announced new research detailing an active credential-stealing malicious skills campaign distributed through Vercel's skills.sh. The affected skill family amassed ...
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they ...
If that answer seems a little anticlimactic, wait until you’ve seen DoomPaint in action before you scoff. Its creator, ...
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange ...