ChainLeak: Critical Chainlit AI Framework Flaws Enable Cloud Environment Takeover
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
Category
Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.
Discord announces mandatory facial scanning and ID uploads months after a breach exposed 70,000 government documents. Users are fleeing to Matrix and TeamSpeak.
Researchers discovered that displaying an AI model's reasoning process creates a roadmap for attackers. OpenAI's o1 rejection rate dropped from 98% to under 2%.
ESET discovers Android malware that queries Google's Gemini AI in real-time to navigate infected devices and maintain persistence across any Android version.
A source-by-source audit of eight AI assistants, what they collect, how training defaults differ, and which privacy settings users can change.
A Cybernews analysis of 1.8 million Android apps found most AI apps leak credentials in code. Over 200M files were exposed via misconfigured databases.
Check Point demonstrated how web-browsing AI assistants can relay malware commands through legitimate traffic. Microsoft changed Copilot's behavior.
Researchers tricked Google Translate's Gemini-based Advanced mode into answering prompts, including requests for drug and malware instructions.
The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.
Research from ELLIS Alicante shows AI reasoning models can autonomously plan and execute attacks that bypass safety guardrails in nearly all other AI systems.
The LayerX Enterprise AI Security Report reveals that AI has become the #1 data exfiltration channel in the enterprise. 82% of those leaking data use personal accounts. Traditional DLP can't stop copy-paste.
The EU Parliament disabled Microsoft Copilot and other AI features on lawmakers' devices, citing data sovereignty concerns and uncertainty about where sensitive information ends up.
Malware caught harvesting OpenClaw configuration files, gateway tokens, and private keys - marking a shift toward AI agent identity theft.
A hardcoded credential and broken authentication in ServiceNow let attackers impersonate any user and weaponize AI agents to create admin backdoors.
Tennessee made it a felony to train AI chatbots that encourage suicide. Virginia is banning AI therapist impersonators. A dozen states have bills moving through legislatures right now.
Security researchers found that messaging apps' link preview feature turns AI agents into zero-click data exfiltration tools. Teams, Slack, Discord, and Telegram are all affected.
ChatGPT's new Lockdown Mode protects against prompt injection data theft - but OpenAI admits the underlying vulnerability may never be solved. Here's what that means for agentic AI.
DHS deployed facial recognition to 100,000+ field encounters without legally required privacy reviews. Internal records show the agency knew the app couldn't verify identities.
Microsoft's GRP-Obliteration technique unaligned 15 major LLMs (OpenAI, Google, Meta, Mistral, Alibaba, DeepSeek) using a single fine-tuning prompt.
CVE-2026-25253 lets attackers hijack OpenClaw AI agents with a single malicious link. Over 135,000 instances are exposed online, many still unpatched.
Companies are using your browsing history, location, and shopping habits to charge you more than the person next to you. California just launched an investigation. Here's how it works.
Security researchers found that Bondu's AI plush toy left its entire admin console open, exposing kids' names, birthdays, and intimate conversations. A senator wants answers.
Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.
Microsoft patches three critical command injection vulnerabilities in GitHub Copilot affecting VS Code, Visual Studio, and JetBrains. Over 20 million developers at risk from unsanitized shell inputs.