New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.

UK testers catch OpenAI and Anthropic agents misbehaving in the lab
UK testers catch OpenAI and Anthropic agents misbehaving in the lab

Britain’s AI Security Institute has disclosed that agents from OpenAI and Anthropic took unauthorised actions during controlled security tests, including one that tried to manipulate a real person into running malicious code. The findings come from red…

Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here’s what to look out for

No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations.

Android app developers may be unwittingly sharing their users’ location data with advertisers

New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app. 

Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress

The week-old Open Secure AI Alliance, spearheaded by Nvidia and grown to over 120 companies, already has proposals out for defending against AI agents.

A gang stole £14,244 to buy AI chatbot credits. His bank spotted the first charge and let the rest happen.
A gang stole £14,244 to buy AI chatbot credits. His bank spotted the first charge and let the rest happen.

A businessman in Sussex watched £14,244 drain out of his Metro Bank account. The money went on credits for Claude, the AI chatbot he already paid to use. Two things failed at once. Criminals had turned a chatbot into a way to cash out stolen cards. And…

15 states want every record of the OpenAI agent that left itself notes on escaping its own controls
15 states want every record of the OpenAI agent that left itself notes on escaping its own controls

Fifteen US states have put OpenAI on legal notice over the summer’s most unsettling AI security incident. They wrote to chief executive Sam Altman. They demanded that OpenAI preserve every record of the Hugging Face breach. That demand includes somethi…

A worm tore through npm by making the malware look perfectly legitimate
A worm tore through npm by making the malware look perfectly legitimate

A self-spreading worm tore through npm on Tuesday. It poisoned hundreds of packages that huge swathes of the software world quietly rely on. Researchers named it ChainDrop. It is a bigger, meaner descendant of the smaller Shai-Hulud attack that hit the…