Tag: supply-chain
All the articles with the tag "supply-chain".
-
Weekly Roundup: Agents Out of Their Sandboxes, and an 860% Cloud Bill
The OpenAI containment story widened for the third time, three labs traced eval escapes to the same test-lab bug, and Amazon found an AI project running 860% over budget.
-
[AUTO] Claude Code auto-executes repository configuration
Claude Code automatically executes MCP configuration from repositories, creating a supply-chain risk when developers switch branches.
-
[AUTO] AI Recommendation Poisoning: the 'Summarize with AI' button that rewrites your assistant's memory
31 companies are hiding memory-planting prompts in 'Summarize with AI' buttons. Here's the attack, the actual injected text, and the npm tool behind it.
-
[AUTO] Paperclip's Real Problem: When Configuration Is Code
Oasis Security's Paperclip research reveals configuration-as-code with server privileges is the real vulnerability, not unique to Paperclip.