| |
Incident CVE-2026-LGTM
A malicious package named foxhole-lz4 passed through seven AI-powered security gates before being detected, each failing for different reasons—including one that misidentified credential theft as standard telemetry. The attack ultimately began and ended the same way: when an autonomous agent read a file it shouldn't have. A human analyst eventually discovered the payload by simply reading the source code, but was rate-limited by GitHub's automated systems before the issue could be escalated.
Read Full Article →
← More Tech news