Skip to content
Intelligibberish
  • News
  • Articles
  • Guides
  • Tools
  • About

Tag

#supply-chain

← All articles

Privacy Jul 18, 2026

Hugging Face's July Breach Was Run by an Autonomous Agent

Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.

Privacy Jul 8, 2026

GitHub's AI Coding Agent Leaked Private Repos With a Single Issue

Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.

Privacy Jul 4, 2026

Alibaba Bars Claude Code Over Backdoor Allegations

Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.

Privacy May 6, 2026

AI Security Roundup: OpenClaw's Nine CVEs in Four Days

OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.

Privacy Apr 28, 2026

AI Security Roundup: Vercel Breached Through AI Tool, n8n's CVSS 10 Nightmare, and the Supply Chain Keeps Breaking

An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.

Privacy Apr 25, 2026

AI Security Roundup: Lovable's 48-Day Open Door, MCP Remote Code Execution, and NIST Abandons 29,000 CVEs

A vibe-coding platform exposed every project's secrets through a trivial API flaw, Anthropic's MCP protocol enables remote code execution across 200,000 servers, and NIST can't keep up with AI-driven vulnerability discovery.

Privacy Apr 20, 2026

AI Security Roundup: Vercel Breached Through an AI Tool, North Korea Weaponized Dependabot, and Your Bot Just Auto-Merged Malware

A third-party AI tool compromise chains into Vercel's systems, North Korean hackers use Dependabot to distribute malware to 895 repos, and courts fine lawyers $145K for AI hallucinations in Q1 alone.

Privacy Apr 17, 2026

AI Security Roundup: Mercor's 4TB Breach, n8n and Langflow RCEs, and the Week AI Workflow Tools Became Attack Surfaces

A supply chain attack exposes 40,000 AI contractors, three major workflow platforms get critical RCE flaws, and Microsoft patches 167 vulnerabilities as AI-driven discovery triples submission rates.

Privacy Apr 11, 2026

AI Security Roundup: Mythos Finds Thousands of Zero-Days, Vibe-Coded CVEs Surge, Flowise Under Active Attack

Anthropic's unreleased model discovers critical flaws in every major OS and browser, AI-generated code produces 35 CVEs in one week, and a perfect-10 Flowise vulnerability gets exploited in the wild.

Privacy Apr 6, 2026

AI Security Roundup: Azure AI Foundry Scores a Perfect 10, Langflow Hijacked in 20 Hours, LiteLLM's Backdoor Cleanup

Microsoft's Azure AI Foundry hit with a maximum-severity privilege escalation, Langflow exploited within hours of disclosure, and LiteLLM discloses three vulnerabilities after surviving a supply chain attack.

Privacy Apr 6, 2026

OpenClaw's Security Meltdown: 9 CVEs in 4 Days, 135K Exposed Instances, and a Poisoned Marketplace

The fastest-growing GitHub project ever just became the biggest AI agent security disaster of 2026. Here's what happened and why it matters.

Privacy Apr 4, 2026

AI Security Roundup: Claude Code Leak Weaponized for Malware, CrewAI's Four Unpatched Flaws

Threat actors turned Anthropic's accidental source code leak into a malware delivery pipeline within hours. Meanwhile, four unpatched CrewAI vulnerabilities let attackers chain prompt injection into full remote code execution.

Privacy Apr 1, 2026

9 CVEs in 4 Days: OpenClaw's Security Crisis Deepens

OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.

Privacy Mar 30, 2026

OpenClaw's March Meltdown: 9 CVEs in 4 Days, 12% of Marketplace Skills Are Malware

OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.

Privacy Mar 29, 2026

TeamPCP Goes Nuclear: Iran-Targeted Kubernetes Wiper, WAV File Steganography, LAPSUS$ Partnership

The supply chain attackers behind Trivy are now wiping Iranian infrastructure, hiding malware in audio files, and extorting enterprises with help from LAPSUS$.

Privacy Mar 29, 2026

AI Security Roundup: TeamPCP Strikes Telnyx, LangChain/LangGraph Vulnerabilities Expose Enterprise Data

TeamPCP's supply chain campaign continues with a WAV file steganography attack on Telnyx. Meanwhile, three vulnerabilities in LangChain and LangGraph can leak files, secrets, and conversation histories.

Privacy Mar 28, 2026

OpenClaw Security Crisis: Industry Rallies as Cisco and OpenClawd Ship Emergency Defenses

After 12% of ClawHub skills turned out to be malware and 135,000 instances were exposed, Cisco releases DefenseClaw and OpenClawd adds verified skill screening. The AI agent ecosystem is racing to catch up.

Privacy Mar 27, 2026

OpenClaw: How the Hottest AI Agent Became a Security Nightmare in Three Weeks

135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.

Privacy Mar 25, 2026

AI Security Roundup: TeamPCP's Supply Chain Rampage, LiteLLM Poisoned, Langflow Exploited in 20 Hours

A coordinated supply chain campaign has compromised Trivy, LiteLLM, and dozens of npm packages. Meanwhile, Langflow attackers built working exploits within hours of disclosure.

Privacy Mar 25, 2026

AI Security Roundup: Trivy Supply Chain Attack Spawns Self-Spreading Worm, Langflow Exploited in 20 Hours

Security scanners become attack vectors, AI agent platforms get RCE'd before patches exist, and 400+ GitHub repos fall to GlassWorm. Plus: a new secrets scanner built for AI coding agents.

Privacy Mar 25, 2026

Trivy Supply Chain Attack: Security Scanner Turned Credential Stealer in GitHub Actions Compromise

TeamPCP hijacked 75 of 76 version tags in Trivy's GitHub Actions, turning the popular vulnerability scanner into a sophisticated credential harvesting operation.

Privacy Mar 19, 2026

OpenClaw's Security Nightmare: 341 Malicious Skills, RCE Vulnerabilities, and the GlassWorm Campaign

The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis

Privacy Mar 18, 2026

GlassWorm Attack Hijacks Hundreds of Python Repos Through Stolen GitHub Tokens

A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.

Analysis Mar 8, 2026

Clinejection: How a GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.

← Newer1 / 2Older →
Intelligibberish

Independent analysis and commentary on artificial intelligence.

News Articles Guides Tools About Disclosure Privacy RSS

© 2026 Intelligibberish. Signal, not noise.