Incident282 iOS AI Apps Exposed Their API Keys
What Happened Researchers at Wake Forest University tested 444 iOS AI chatbot applications and found that 282 of them—63%—transmitted API keys in plaintext through network traffic. These keys granted
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened Researchers at Wake Forest University tested 444 iOS AI chatbot applications and found that 282 of them—63%—transmitted API keys in plaintext through network traffic. These keys granted
IncidentWhat Happened Attackers published at least eight malicious packages to the Python Package Index (PyPI), each pretending to be a legitimate fork of Pyrogram, a popular Python framework for building Tel
IncidentWhat Happened Mozilla s Zero Day Investigative Network (0DIN) documented an indirect prompt injection attack against Claude Code, an AI-powered coding assistant. A developer used the agent to interact
IncidentThe Growing Security Debt in AI Organizations rushing to deploy AI features are creating a security backlog they cannot manage. According to Cobalt s AI and Pentesting Pulse Report 2026, AI and LLM ap
Get weekly security insights and compliance updates delivered to your inbox.
GeneralIf you ve ever watched a junior pentester run Nmap without understanding what they re looking for, you ve seen the problem AI-driven security tools must solve. Automation without reasoning creates noi
IncidentThe Issue at Hand Between 2017 and 2018, ReDoS (Regular Expression Denial of Service) vulnerabilities in npm packages surged by 143%. This wasn t an isolated incident but a widespread issue across the
IncidentUnderstanding the Vulnerability On February 11, 2019, security researchers disclosed CVE-2019-5736 , a critical vulnerability in runC that allows a malicious container to overwrite the host s runC bin
IncidentThe Growing Threat of Third-Party Library Vulnerabilities Between 2022 and 2024, vulnerabilities in application libraries surged by 88%. This isn t just a story of breaches—it s about the growing tech
IncidentThe Hidden Risk in Your Dependency Tree Snyk s analysis of over one million open source projects revealed a significant supply chain issue: 78% of vulnerabilities exist in indirect dependencies—the pa
IncidentOn May 25, 2026, attackers uploaded compromised npm packages that exploited Visual Studio Code to deploy InvisibleFerret, a Python-based information stealer. The attack targeted developers on Windows,
IncidentWhat Happened On April 18, 2019, security researchers disclosed a CRLF injection vulnerability in urllib3 , a Python HTTP client library foundational to over 500 open-source libraries. This vulnerabil
IncidentWhat Happened On July 2, 2019, Snyk published CVE-2019-10744 , a prototype pollution vulnerability affecting every version of lodash. This library, used by 4.35 million projects on GitHub and download
IncidentOverview of the Issue A security analysis of the .NET ecosystem has highlighted a significant concentration of critical vulnerabilities that require immediate attention from your security team. Remote
IncidentThe Issue at Hand The jQuery team released version 3.4.0 to address a prototype pollution vulnerability in the library s object extension functionality. Researcher Olivier Arteau identified the flaw,
IncidentOn April 25, 2019, Docker Hub discovered unauthorized access to a database containing user data. Approximately 190,000 accounts were affected, exposing usernames, hashed passwords, and GitHub and Bitb
IncidentWhat Happened A malicious npm package named electron-native-notify targeted users of Komodo s Agama cryptocurrency wallet. A GitHub user, sawlysawly, disclosed the threat via a public commit, triggeri