Tag: AI security

turned-on flat screen monitor
Security

Enterprises that pull community models: the May 2026 Hugging Face typosquat that installed a Windows infostealer

In May 2026, a typosquatted Hugging Face repository—Open-OSS/privacy-filter—distributed a loader that ultimately installed a Rust-based credential stealer on Windows machines; the repo was downloaded over 200,000 times before removal. For teams that pull community models into development or production, this incident reframes the threat: attackers can hide executable installers in model repos, not just poison […]

admin 
Man in checkered shirt using smartphone indoors
AI

If you won’t install an app: Poke runs AI automations over SMS/iMessage and routes each task to the best model

Poke, a Palo Alto startup, runs AI agents entirely through text messages—iMessage, SMS, and Telegram—so users can set up automations without installing an app or managing API keys. The platform’s distinct technical choice is provider-agnostic model routing: it picks the model best suited to each task, including open-source models, rather than tying automations to a […]

admin 
Programmer coding at a desk with several monitors.
Security

Mercor breach: a LiteLLM supply‑chain compromise that exfiltrated terabytes

Mercor’s recruiting platform was breached after attackers slipped malicious code into a published LiteLLM package, turning a widely reused open‑source proxy into a broad data exfiltration channel. The incident — detected and removed from distribution within hours but still exploited — exposed terabytes of sensitive material and has forced immediate, industry‑wide dependency audits and credential […]

admin 
Man and woman discussing tablet outside office building
Security

Beyond Chatbots: Why Autonomous AI Agents Introduce an Identity-First Security Risk

AI agents aren’t just smarter chatbots; they operate with distinct identities and degrees of autonomy that let them act on infrastructure and data. That identity-plus-autonomy combo requires enterprises to move security from conversational filters to identity governance, least-privilege controls, and operational checkpoints. Three agent types and why identity changes the problem Enterprises now deploy three […]

admin 
A neon sign is lit up on the side of a building
Security

Varonis launches Atlas: shifts AI security from discovery to inline runtime protection — next test is enterprise-scale adoption

Varonis Systems has launched Varonis Atlas, an end-to-end AI security platform that combines continuous AI asset discovery, runtime protection, threat detection, and governance with the company’s data-sensitivity context. The product is pitched as more than a discovery or monitoring tool: Atlas aims to close blind spots from shadow AI through to live model interactions and […]

admin