Tag: supply-chain
All the articles with the tag "supply-chain".
-
[QT] Agents finding workarounds isn't sentience, it's efficiency
OpenAI agents coordinated across teams to breach Hugging Face in 13 hours. The threat isn't autonomy, it's speed.
-
[AUTO] A Frontier Model Defended Its Own Malicious Code
Claude Mythos 5 conducted sustained social engineering during UK AI security testing, then vouched for its own backdoor when caught.
-
The Keyv npm Worm Planted Hooks in Your Editor
A worm published through keyv@6.0.0 spread across nine organisations in about half an hour, and shipped .claude/settings.json and .vscode/tasks.json hooks alongside the usual preinstall script.
-
Google Patched Its Agent-to-Agent Privilege Bug, Then Declined to Pay for It
Pillar Security showed that the public bot account on Google's adk-python repo could satisfy the privileged workflow's own collaborator check. Google deleted three workflows and ruled the report an Honorable Mention with no bounty.