This week's Wild West roundup:
This week's Wild West roundup: Context Collapse, Part 3 - AI Worming through Word. This LLM worm was reported to Microsoft months ago, but it's not possible to patch. Shar...
41 chunks · 41 episodes
This week's Wild West roundup: Context Collapse, Part 3 - AI Worming through Word. This LLM worm was reported to Microsoft months ago, but it's not possible to patch. Shar...
This week's Wild West Roundup: Claude Code Seals Bash and Unicode Bypass Gaps in Agentic Permission Layer. "Two bypass classes that could slip commands past auto mode perm...
This week in the Wild West Roundup: Axios: Exclusive: Google patched AI chatbot flaw that could have exposed customer conversations. When even mainstream news publications are ...
This week in the Wild West Roundup: Clone This Repo and I Own Your Machine. DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE. Exploitin...
This week in the Wild West Roundup. MacOS.Gaslight: Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox. Multiple malicious OpenClaw skills found online - incl...
This week in the Wild West roundup: SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon "Varonis Threat Labs discovered SearchLeak, a critical vuln...
This week in the Wild West Roundup. Securing CI/CD in an agentic world: Claude Code Github action case. "Microsoft Threat Intelligence discovered that Anthropic's Claude Code G...
This week's Wild West Roundup: Ars: Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts. "Pricey Instagram handles were stolen and resold before Me...
This week in the Wild West Roundup: Microsoft Copilot Cowork Exfiltrates Files. ChatGPPhish: ChatGPT blindly trusts browser content, turning the page into a payload. Ars Techni...
This week in the Wild West Roundup: Critical 'Claw Chain' Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk. The Register: Minor edits to AI skills can make agents g...
This week in the Wild West Roundup: Mean Pooling Was Hiding Prompt Injections in Our RAG Pipeline. Using Bedrock with Claude Code? Your AWS Credentials Are Shared With Every Su...
This week in the Wild West Roundup: Someone Used Morse Code to Trick Grok Into Sending $174,000 and It Has Happened Before. Vulnerability in Claude Extension for Chrome Exposes...
This week in the Wild West Roundup. Google's Threat Intelligence Group saw a 32% relative increase in malicious Indirect Prompt Injection between November and February in the w...
This week's Wild West Roundup: 10 Indirect Prompt Injection Payloads Caught in the Wild. Prompt Injection leads to RCE and Sandbox Escape in Antigravity. The Mother of All...
This week in the Wild West Roundup: A real Google Maps place page with tons of prompt injection in the comments. 'Comment and Control': Claude Code, Gemini CLI, GitHub Copilot ...
This week in the Wild West Roundup. Paper: "A scan of approximately 2,000 MCP servers found all lacked authentication." Google DeepMind Researchers Map Web Attacks Against AI A...
This week in the Wild West Roundup: ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime. A roundup: OpenClaw Security Report CrewAI Vulnerabilities...
This week in the Wild West roundup: Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website OpenClaw Agents Can Be Guilt-Tripped Into Self-Sabotage. "In a...
This week's Wild West roundup: Claudy Day: an exfiltration that can happen entirely in a default Claude session. A rogue AI led to a serious security incident at Meta. Vul...
This week's Wild West roundup: Researchers Trick Perplexity's Comet AI Browser Into Phishing Scam in Under Four Minutes. ScamAgent: AI Agent Built by Researchers that Run ...