Tag
The article discusses a research paper where LLMs used to write and review a trading feature missed a future-data bug, highlighting the need for structural redesigns in agent systems to prevent such issues.
Cybersecurity researcher Piotr Solowewicz bought the domain noreply.net and discovered thousands of companies are sending sensitive emails to it due to misconfigured settings, highlighting a widespread data-leakage problem.
Security researcher Cory Solovewicz, owner of noreply.us and noreply.net, has received hundreds of thousands of misdirected emails containing sensitive information from companies and organizations, and he presented his findings at Defcon.
Cursor, an AI-powered code editor, is reportedly sending users' codebase data to its servers even when telemetry settings are disabled, raising privacy concerns.
Anthropic's Claude chat sharing feature is public by default, causing users' sensitive conversations (such as cryptocurrency keys, private stories) to be discoverable via simple Google Dork searches. Although Anthropic has started removing pages, old links remain visible on search engines like Yahoo.
Prism inadvertently leaked user papers due to a compilation bug that returned someone else's paper, prompting a quick takedown within 10 minutes of being flagged.
A security researcher discovered that asking Claude.ai about a coffeeshop caused the model to leak personal information (full name, employer, bank security answers) to a malicious attacker without any code execution or MCPs.
xAI's Grok Build CLI was found to be uploading entire Git repositories to a Google Cloud bucket, including private code and secrets, without proper disclosure or acknowledgment.
CISA's postmortem on a GitHub leak of internal credentials highlights critical incident response failures, including delayed key rotation and ignored automated alerts, offering key lessons for security teams.
A user reports that the Grok CLI tool uploaded their entire home directory, including SSH keys and password databases, to xAI's servers, raising serious privacy and security concerns.
Noma Labs discovered a critical prompt injection vulnerability in GitHub's Agentic Workflows, allowing unauthenticated attackers to exfiltrate data from private repositories by posting a crafted GitHub issue in a public repository of the same organization.
The Mercor breach through the LiteLLM open-source library exposed systemic vulnerabilities in AI training data security, revealing that the data layer—often less protected than model weights—is a prime target for attackers.
An incident where Google's Gemini AI model inadvertently shared another user's chat history with the poster.
Meta has paused its employee-tracking program, the Model Compatibility Initiative (MCI), after an internal security breach exposed sensitive data collected from workers, following employee protests and privacy concerns.
A company's billing chatbot is sharing transaction histories and financial data with anyone who provides the correct account number, highlighting a lack of proper guardrails against data leakage and the need for better AI safety measures.
Lawmakers demand answers after a CISA contractor intentionally exposed AWS GovCloud keys and other secrets on a public GitHub repository, raising concerns about the agency's security culture amid staffing disruptions.
Trump Mobile is accused of insecurely storing customer data, potentially leaking addresses and phone numbers from T1 Phone pre-orders. The leak also reveals order numbers far lower than viral claims.
A CISA contractor leaked highly privileged AWS GovCloud credentials and internal system passwords on a public GitHub repository, representing one of the most egregious government data leaks in recent history.
A critical privacy flaw in DeepSeek allows users to access each other's conversations by entering a specific character, breaking session isolation and exposing sensitive data.
AI chatbots like Gemini, ChatGPT, and Claude are exposing real phone numbers and personal information due to training data containing PII, causing a 400% increase in privacy-related queries to services like DeleteMe.