A fake repo impersonating the OpenAI Privacy Filter model racked up 244,000 downloads in under 18 hours before Hugging Face ...
TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm ...
The repository reached the #1 trending position on Hugging Face within 18 hours, highlighting how public AI repositories are ...
Fake OpenAI Privacy Filter hit #1 on Hugging Face with 244,000 downloads, spreading infostealer malware to Windows users.
Our '7 Days' weekly tech roundup brings the juiciest announcements. Read about Edge browser handling passwords in plaintext, JDownloader getting hacked, and the TAB key.
The 4GB on-device AI model, supposedly for Gemini Nano, is installed without consent or opt-in, and even re-downloads itself ...
A malicious repository on Hugging Face impersonated OpenAI’s “Privacy Filter” project and briefly reached the platform’s top trending position before removal ...
A 6MB editor quietly replacing tools that cost ten times more.
Researchers demonstrate how attackers can weaponize trusted repositories to hijack AI coding assistants and compromise ...
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands.
OX Security confirmed arbitrary command execution on six live platforms and estimates 200,000 MCP servers are exposed. Here's ...
The least exciting page in your browser is also the easiest one to vibe-code.