French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them. The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks… Read More "CrowdSec Confirms Source Code Stolen in Supply Chain Attack"
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained… Read More "AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code"