TECH.
FOR.
HUMANS.
One GitHub Issue Should Not Be Able to Steer Your Coding Agent
A Claude Code GitHub Action flaw showed how AI issue triage, broad repo permissions, and prompt injection can become a supply-chain problem.
I write about security, privacy, and AI — the stuff that matters but rarely gets explained well. Practical, opinionated, honest.
No fear-mongering. No affiliate tax. Just the plain-English version.
LATEST
67 articles and counting. Newest first.
Your AI Assistant Should Not Believe Your Notifications
A patched Google Gemini bug showed how a hostile WhatsApp or Slack notification could steer an Android assistant. The fix matters, but the design lesson matters more.
The Patch Window Is Gone
Android, WebLogic, WinRAR, and AI-assisted exploit tooling all point at the same boring truth: patching slowly is becoming a security decision, not an operations delay.
The npm Worm Is Now in the AI Toolchain
Miasma, codexui-android, and the Meta support-bot incident all point at the same uncomfortable pattern: developer and AI workflows are becoming account-recovery, credential, and deployment surfaces.
Your AI Agent's Memory Is Now an Attack Surface
OWASP Agent Memory Guard is a useful signal: the dangerous part of agent memory is not only what the model remembers. It is who gets to write into that memory, when, and how long the poison survives.
A Website Should Not Be Able to Watch Your SSD
FROST is a browser side channel that uses OPFS storage timing and SSD contention to infer what else is happening on your machine. It is not a catastrophe. It is a warning about how much power we keep handing to ordinary web pages.
ChatGPT Is Becoming a Browser Surface, and Attackers Noticed
Two incidents this week point to the same shift: AI assistants are no longer just tools you ask questions. They are trusted rendering surfaces, link brokers, and post-exploitation operators. That changes the security model.
- highPCPJack Turns 230 Cloud Servers Into a Covert SMTP Relay NetworkThe Hacker NewsJun 5
- mediumAgentGG Brings Open-Source Agentic SAST to Code ReviewHelp Net SecurityJun 5
- highClaude Code GitHub Action Flaw Let a Malicious Issue Reach Repo Write TokensGMO Flatt Security / The Hacker NewsJun 4
- criticalCisco Patches Unified CM SSRF After Exploit Code Goes PublicThe Hacker NewsJun 4