Overview On July 11, 2026, two researchers from the ASSET Research Group at the University of Missouri-Kansas City, Sudipta Chattopadhyay and Murali Ediga, disclosed a novel attack technique named Ghostcommit. This attack is capable of exfiltrating the entire contents of a target's .env file. The ingenuity of this attack lies...
Tag: AI security
AI Security Incident Case: JadePuffer Ransomware Leverages AI Agent to Automate Attacks
In early July 2026, security firm Sysdig publicly disclosed a new type of ransomware attack. After gaining initial access by exploiting a Langflow vulnerability (CVE-2025-3248), the JadePuffer ransomware leveraged a Large Language Model (LLM) agent to automatically execute the entire attack chain. From reconnaissance, credential theft, lateral movement, and privilege...
AI Security Incident Case: Miasma Worm Attacked Microsoft GitHub
Overview On June 5, 2026, 73 of Microsoft's GitHub repositories were batch-disabled within 105 seconds, triggered when a developer opened a contaminated project folder using VS Code. The attack originated from the Miasma worm, a self-replicating supply chain attack tool operated by TeamPCP. It shifted the attack entry point forward...
AI Security Incident Case: Jetbrains Plugin Supply Chain Attack Stealing AI Key
Overview In June 2026, the security research team Aikido detected a batch of collaborative malicious plugins in the JetBrains plugin market, totaling 15 plugins with nearly 70,000 cumulative installations. All of them would silently leak the AI service provider's API key to the attacker's server at the moment when the...
AI Security Incident Case: From Claude Code Sandbox Bypass to the Boundary Failure in the Age of AI Agents
Overview In early June 2026, the security community disclosed a number of AI-related security incidents, triggering a re-examination of the industry's security boundaries for AI agent systems. The Anthropic Claude Code network sandbox bypass vulnerability, rumors of related service anomalies, and AI toolchain-based attacks appeared in the same time window,...
AI Security Incident Case: Account Takeover Due to Meta AI Support Assistant Authorization Flaw
Overview Between late May and early June 2026, several high-profile Instagram accounts were reportedly taken over by attackers, including Barack Obama's White House account, the personal account of U.S. Space Force Chief Master Sergeant Bentivegna, and the official account of beauty brand Sephora. Security researchers later discovered videos and screenshots...




