Skip to content
Intelligibberish
  • News
  • Articles
  • Guides
  • Tools
  • About

Tag

#supply-chain

← All articles

Privacy Mar 18, 2026

GlassWorm Attack Hijacks Hundreds of Python Repos Through Stolen GitHub Tokens

A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.

Analysis Mar 8, 2026

Clinejection: How a GitHub Issue Title Compromised 4,000 Developer Machines

A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.

Privacy Feb 21, 2026

ChainLeak: Critical Chainlit AI Framework Flaws Enable Cloud Environment Takeover

Two vulnerabilities in the popular Chainlit AI framework allow attackers to steal cloud credentials, API keys, and user data from enterprise chatbots.

Analysis Feb 20, 2026

AI Reads 67,000 Papers, Finds 25 Magnets to Break China's Grip

UNH team built an AI that extracted magnetic data from 67,573 papers, identifying 25 new high-temperature magnets to replace rare earths in EVs.

Privacy Feb 20, 2026

OpenClaw's Month From Hell: 40K Exposed, Corporate Bans

The viral AI agent went from 135K GitHub stars to enterprise blacklists in three weeks. Here's what went wrong and why it matters for every AI agent.

Analysis Feb 19, 2026

AI Memory Shortage: Why Consumer Electronics Cost More

AI data-center demand is squeezing DRAM supply, raising memory and device prices as manufacturers prioritize higher-margin HBM.

Privacy Feb 12, 2026

DockerDash: How Poisoned Container Metadata Turned Docker's AI Assistant Into an Attack Vector

Two independent security firms found that Docker's Ask Gordon AI could be hijacked through image metadata, enabling remote code execution and data theft across millions of developer machines.

Privacy Feb 6, 2026

341 Malicious AI Agent Plugins Were Hiding in Plain Sight on ClawHub

OpenClaw's skills marketplace was weaponized to steal passwords and crypto wallets. A single attacker published 314 fake tools. This is what happens when AI agents get app stores.

Privacy Feb 5, 2026

341 Malicious Skills Found on ClawHub: The First Major AI Agent Supply Chain Attack

Security researchers discovered hundreds of malware-laced OpenClaw skills stealing crypto wallets, passwords, and API keys. The AI agent ecosystem just got its npm moment.

Privacy Feb 5, 2026

DockerDash: How Metadata Hijacks Docker's AI Assistant

A Docker AI vulnerability let attackers embed commands in image labels. Patched months ago, the pattern keeps recurring.

← Newer2 / 2Older →
Intelligibberish

Making sense of AI overwhelm. Independent, self-hosted, no trackers.

News Articles Guides Tools About Disclosure Privacy RSS

© 2026 Intelligibberish. Making sense of AI overwhelm.