NuGet API key expiration 2026: Microsoft caps new NuGet.org API keys at 30 days starting August 17, forcing all existing keys ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave ...
Threat-intelligence firm CloudSEK said in a report published August 11, 2026 that it has identified more than 2,500 organizations potentially exposed by the March 2026 supply-chain compromise of ...
Security researcher Kevin Beaumont got a call last week from a major US technology company that insisted it had nothing to worry about: all the credentials stolen in March's LiteLLM supply chain ...
Researchers found every major AI provider encrypts reasoning tokens with a single global key—and exploited it to decode a trove of data.
When AI agents get compromised, new research shows the model usually isn’t to blame — the code wrapped around it is. And most organizations aren’t watching it closely enough.
A new project aims to build a shared, open source AI training dataset that anyone can contribute to, much like an open source software project. It aims to make training data more transparent than that ...
Encrypted AI reasoning vulnerability in Anthropic, OpenAI, and Google APIs let researchers decode 315,320 published session ...
Most of the 2,500 organizations believed to have been affected by the LiteLLM supply chain attack were actually exposed before, SOCRadar reports. The compromise was blamed on and claimed by TeamPCP, ...
Spread the loveIf you’ve spent any time at all working with APIs, you know the drill: you’re constantly juggling different ...
Spread the loveWhen you’re building modern applications, APIs are the backbone. They’re how different software components ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results