AI Security Roundup

Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.

ai-security EN

Selective HTTP Proxying in Linux, (Thu, May 21st)

Recently, Rob wrote about a tool, Proxifier , that can intercept requests from specific processes. Proxifier is available for Windows, macOS, and Android. But I have not seen a generic Linux option …

ai-security EN

Cross-Platform NPM Stealer, (Fri, May 22nd)

I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as “extracted-decoded.js” (and reformated). The SHA256 is …

ai-security EN

We hardened zizmor's GitHub Actions static analyzer

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials …

ai-security EN

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS …

ai-security EN

Zero-Day Exploit Against Windows BitLocker

Zero-Day Exploit Against Windows BitLocker It’s nasty , but it requires physical access to the computer: > The exploit, named YellowKey, was > published > earlier this week by a researcher …

ai-security EN

On AI Security

On AI Security Good report : > Executive Summary: > Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, …

ai-security EN

macOS Kernel Memory Corruption Exploit

macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article . Tags: AI , Apple , …

ai-security EN

Laurie Anderson Is Quoting Me

Laurie Anderson Is Quoting Me Not by name, but Laurie Anderson quotes me in one of the tracks of her new album: > My favorite quote is from a cryptologist who said “If you think technology will …

ai-security EN

CISA Security Leak

CISA Security Leak Crazy story : > Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed …