Sign in

Ax Sharma

@axsharma.com
566 followers 362 following 87 posts

Journalist and Security Researcher. Bylines/seen on: BleepingComputer, BBC, Channel 5, TechCrunch, WIRED. 📍🇨🇦 | 🇬🇧 | 🇮🇳 www.axsharma.com X/Twitter: @Ax_Sharma

PostsRepliesMedia
Ax Sharma @axsharma.com · 26/09/2026
Yesterday we named SEC[.]gov, investor[.]gov, Census and MAX[.]gov in the OpenAI agent story. Today Bloomberg and NYT report OpenAI's agents targeted SEC, Investor and Census data, calling it "routine research." Not quite: agents tried '../' path traversal on SEC, as we state:
100
Ax Sharma @axsharma.com · 05/09/2026
Today, OpenAI admitted it didn't disclose an incident where its autonomous agents hijacked a German wiki to pool answers, cheat on tasks, and share sandbox bypasses. OpenAI earlier considered it a "misalignment". Researchers recovered roughly 18,000 posts 👇 www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as mode...
050
Ax Sharma @axsharma.com · 30/08/2026
Exclusive: FulcrumSec claims the Manchester Airports hack and says it stole 86 GB of data. We validated one traveller's record, finding booking and travel data beyond MAG's disclosure: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information be...
010
Ax Sharma @axsharma.com · 31/07/2026
You don't run code on people who haven't agreed to it. That norm has ended careers. Claude uploaded live malware to PyPI in a botched eval and 15 real systems ran it. It even maneuvered around restrictions to squat a phantom dependency and breached 3 orgs. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendo...
141
Ax Sharma @axsharma.com · 22/07/2026
[1/2] A VS Code extension called 'Markdown All Pro' impersonates a legit one with 14 million installs. Installing it ships your machine's details off-box and opens a channel the operator can feed anything to later, no update to the extension needed!
100
Ax Sharma @axsharma.com · 20/07/2026
Pillar Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity, without attacking the sandbox head-on. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ...
181
Ax Sharma @axsharma.com · 14/07/2026
Remember ClaudeBleed? The Claude for Chrome fix that didn't fix it. 2 new flaws, reported in May, marked resolved. 8 versions later, both still reproduce! Any other extension you've installed can push Claude into reading your Gmail. 🔗 Full breakdown: www.manifold.security/blog/claude-...
manifold.security
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail - Manifold Security
Two flaws in Claude for Chrome let any browser extension read a victim's Gmail, Docs, and Calendar. Reported to Anthropic in May, still live in v1.0.80. Vertical
000
Ax Sharma @axsharma.com · 11/07/2026
An AI code reviewer just approved a pull request that steals your secrets. It never saw it coming as the attack was hidden in a PNG. Researchers put the malicious instruction inside an image. The reviewer never opened it, so the poisoned PR merged clean! www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open im...
020
Ax Sharma @axsharma.com · 17/06/2026
Google's about to start using UK and EU user IP addresses for ad personalization, from Aug 3. In 2019 Google called this kind of fingerprinting "wrong." The ICO called the 2024 reversal "irresponsible." It's happening anyway. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Google to use UK and EU user IP addresses for ad personalization
From August 3, 2026, Google will use IP addresses from UK, EEA and Switzerland users for ad measurement and personalization. It lands as the ICO weighs new consent rules, and years after Google itself...
010
Ax Sharma @axsharma.com · 16/06/2026
Everyone's covering the UK's under-16 social media ban. The under-covered bit: enforcing it means opening any new account will require an ID or face scan, effectively ending anonymity. Experts warn circumvention is easy and your biometric data is at risk. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
UK to require ID or face scan before you can make social media accounts
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security ex...
002
Ax Sharma @axsharma.com · 15/06/2026
Every useful AI agent today reads private data, processes untrusted content, and communicates externally. By design. That's also the exact profile researchers used to flag as a near-guaranteed sign of exploitation. So, how do you separate signal from noise? www.csoonline.com/article/4184...
csoonline.com
5 runtime signals for catching a compromised AI agent
Once a signal of exploitation risk, Willison’s ‘lethal trifecta’ describes the baseline operations of every AI agent today. As a result, agent security is no longer architectural. Here’s what to watch...
000
Ax Sharma @axsharma.com · 13/06/2026
US gov ordered Anthropic to pull Fable 5 + Mythos 5 for all "foreign nationals" ... so effectively worldwide. The trigger being a narrow jailbreak where you ask the model to read a codebase and fix bugs. But, the capability is anyway widely available (from other models like GPT-5.5).
100
Ax Sharma @axsharma.com · 04/06/2026
We disclosed a critical flaw in n8n-mcp (120k+ weekly npm downloads). On shared multi-tenant setups, one user could read everyone else's workflow backups, API keys and tokens included, or *wipe them all* in a single call. Just by guessing a number. CVSS 9.6. Found by Franciso Rosales. 🧵
110
Ax Sharma @axsharma.com · 20/05/2026
A trojanized Bitwarden npm version appeared for 90 minutes last month. 9 days later it got a CVE—after the package was already pulled. That's an incident response notification, not what CVEs were originally built for. Agentic AI makes this gap much worse. www.csoonline.com/article/4173...
csoonline.com
Why some security fixes never reach your vulnerability dashboard
CVE was built to track code flaws with fixes. It’s now being stretched to cover malware and supply chain incidents that don’t fit. Agent infrastructure and AI assets are where that drift becomes struc...
010
Ax Sharma @axsharma.com · 18/05/2026
The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵
110
Ax Sharma @axsharma.com · 14/05/2026
We scanned 19,000+ AI agent skills. One enterprise scanner flagged 40%+ as malicious. Most were fine. A skill called "derp" passed two of three scanners clean. It instructs agents to silently produce broken code, and blame the developer's environment if they get suspicious.
100
Ax Sharma @axsharma.com · 10/05/2026
Hackers are abusing Google Ads + real Claude[.]ai shared chats to push Mac malware. The Google ad URL is genuine, so there's no lookalike domain to catch. Two active variants seen so far, one with CIS geofencing: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come across sponsored search results that list ...
152
Ax Sharma @axsharma.com · 10/03/2026
Who are AI safety guardrails actually protecting? I've been researching this for a few weeks, and the honest answer is... not always the right people. Defenders and security researchers often face friction, while attackers just walk around safety guardrails: www.csoonline.com/article/4138...
csoonline.com
When AI safety constrains defenders more than attackers
AI guardrails increasingly block legitimate security work while attackers bypass restrictions with ease. For CISOs, this asymmetry creates blind spots in defensive capabilities.
000
Ax Sharma @axsharma.com · 19/02/2026
⚠️ Seeing a lot of exaggerated or misleading posts about the recent Cline CLI supply chain incident, so here’s some context. Feb 17 incident is clearly documented in the low-severity advisory: github.com/cline/cline/...
github.com
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw
### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...
100
Ax Sharma @axsharma.com · 16/02/2026
Canada Goose says it is reviewing a 1.67 GB dataset leaked by ShinyHunters extortion group, with more than 600,000 customer records.
110
Ax Sharma @axsharma.com · 07/02/2026
🚨 Nationwide payment card-processing outage tied to #ransomware attack. Payments platform BridgePay confirms a #ransomware attack has knocked key systems offline, impacting merchants and municipal services across the U.S. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Payments platform BridgePay confirms ransomware attack behind outage
A major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday a...
110
Ax Sharma @axsharma.com · 05/02/2026
Despite #Zendesk suggesting safeguards and tightening up security last month, the massive spam wave has returned flooding inboxes with hundreds of bogus 'Activate account...' emails that bypass #spam filters www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Zendesk spam wave returns, floods users with 'Activate account' emails
A fresh wave of spam is hitting inboxes worldwide, with users reporting that they are once again being bombarded by automated emails generated through companies' unsecured Zendesk support systems. Som...
122
Ax Sharma @axsharma.com · 02/02/2026
Responsible disclosure is built on an assumption that "doing the right thing" would = timely action, fair treatment, and maybe a bounty reward. Lately, that assumption is collapsing. For CISOs, this is gradually becoming a risk management nightmare. www.csoonline.com/article/4124...
csoonline.com
When responsible disclosure becomes unpaid labor
An incentive gap is undermining responsible disclosure. For CISOs, this is gradually evolving into a risk management nightmare.
010
Ax Sharma @axsharma.com · 02/02/2026
A NationStates game player found a critical vulnerability but then crossed a line: he copied production data and app code. Finding a flaw is enough. Demonstrate it safely, report it and stop there. Holding data isn't clever, ever. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
NationStates confirms data breach, shuts down game site
NationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.
113
Ax Sharma @axsharma.com · 14/01/2026
BREAKING: Threat actors are seeking data on ~1,800 MSPs after a Pax8 spreadsheet with customer and Microsoft licensing info was accidentally emailed to over three dozen partners yesterday. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP cust...
110
Ax Sharma @axsharma.com · 13/01/2026
Heads up: A new #phishing campaign is abusing LinkedIn comment-replies and directing users to external links to lift a bogus "temporary restriction." www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Convincing LinkedIn comment-reply tactic used in new phishing
Scammers are flooding LinkedIn posts with fake "reply" comments that appear to come from the platform, warning of bogus policy violations and urging users to click external links. Some even abuse Link...
222
Ax Sharma @axsharma.com · 13/01/2026
⚠️ Telegram privacy alert: Don't tap any @usernames or links in chats. These can actually be hidden proxy URLs. Tapping them just once can trigger a direct connection that reveals your real IP address to a third party with one click: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hidden Telegram proxy links can reveal your IP address in one click
A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add w...
110
Ax Sharma @axsharma.com · 13/01/2026
Update: Multiple current and former Target employees have reached out to confirm that the source code and documentation shared by a threat actor match real internal systems. A company-wide Slack announcement also announced "accelerated" access changes. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Target employees confirm leaked code after ‘accelerated’ Git lockdown
Multiple current and former Target employees confirmed that leaked source code samples posted by a threat actor match real internal systems. The company also rolled out an "accelerated" lockdown of it...
111
Ax Sharma @axsharma.com · 12/01/2026
EXCLUSIVE: Target's developer Git server went offline shortly after hackers claimed they had stolen internal source code and published what they claim are sample repositories for sale. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Target's dev server offline after hackers claim to steal source code
Hackers are claiming to be selling internal source code belonging to Target Corporation, after publishing what appears to be a sample of stolen code repositories on a public software development platf...
100
Ax Sharma @axsharma.com · 06/01/2026
Microsoft Copilot prompt injections—vulnerabilities or AI limits? Microsoft implies that these don't constitute "serviceable vulnerabilities." But security pros are divided, especially when AIs like Claude restrict inputs that can cause system prompt leaks. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Are Copilot prompt injection flaws vulnerabilities or AI limits?
Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The de...
011
Reposted by Ax Sharma
Cynthia Brumfield @metacurity.com · 01/01/2026
What an awful perk this is...it's saying "hey, get addicted to nicotine so we can squeeze more ideas out of you." Tech Startups Are Handing Out Free Nicotine Pouches to Boost Productivity www.wsj.com/tech/tech-st...
wsj.com
Tech Startups Are Handing Out Free Nicotine Pouches to Boost Productivity
A nicotine replacement for smokers has started popping up in offices in the tech industry, despite health hazards.
43512
Ax Sharma @axsharma.com · 22/12/2025
Not all CISA KEV listings mean urgent risk. CVE-2025-59374 formalizes the 2019 ASUS ShadowHammer supply-chain attack, not a new exploit. FAQ updates, older guidance, and new context shared by CISA below signal a classification effort, not an active threat. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374
An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the ...
110
Ax Sharma @axsharma.com · 28/11/2025
Can't believe but... the "real" flight ticket trick is still claiming victims. 🎫✈️ Scammers sell "tickets" that appear valid on the airline website for days, and then vanish. I'd written about this exact scam in 2023: www.wired.com/story/plane-...
110
Ax Sharma @axsharma.com · 26/11/2025
I was on BBC #RipOffBritain today breaking down code behind a fake "Google Movie" task scam site that conned many £££. But worse is, real cases of victims losing their PayPal balances and then getting locked out of dispute process in a catch-22. 📡 Next episode: Friday 10.45am
110
Ax Sharma @axsharma.com · 23/11/2025
Iberia is notifying customers of a data security incident stemming from a vendor compromise. Disclosure follows a threat actor's claims on hacker forums that they had access to 77 GB of the airline's data. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Iberia discloses customer data leak after vendor security breach
Spanish flag carrier Iberia has begun notifying customers of a data security incident stemming from a compromise at one of its suppliers. The disclosure comes days after a threat actor claimed on hack...
010
Ax Sharma @axsharma.com · 17/11/2025
Exclusive: DoorDash email spoofing vulnerability disclosure goes off-track. The researcher contends the company ignored the issue until pressured. The company says the pressure, which it deems extortion, itself crossed ethical lines. www.bleepingcomputer.com/news/securit... #bugbounty #hacking
bleepingcomputer.com
DoorDash email spoofing vulnerability sparks messy disclosure dispute
A vulnerability in DoorDash's systems could allow anyone to send "official" DoorDash-themed emails right from company's authorized servers, paving a near-perfect phishing channel. DoorDash has now pat...
020
Reposted by Ax Sharma
andy jabbour @andyjabbour.bsky.social · 14/11/2025
🇦🇺 ASD: Annual Cyber Threat Report 2024-2025. What ASD's ACSC saw: www.cyber.gov.au/about-us/vie... #australia #cybersecurity cc @gate15.bsky.social @campuscodi.risky.biz
057
Ax Sharma @axsharma.com · 14/11/2025
DoorDash has disclosed a new data breach from 19 days ago: customer names, addresses, phone numbers and emails have been accessed. The cause? A social engineering attack on an employee. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
DoorDash hit by yet another data breach this October
DoorDash has disclosed a data breach that hit the food delivery platform this October. Beginning yesterday evening, DoorDash, which serves millions of customers across the U.S., Canada, Australia, and...
130
Ax Sharma @axsharma.com · 06/11/2025
The world's largest software supply chain attack stole just $600, but cost teams thousands of engineering hours. Modern supply chain attacks are evolving and shaping the threat landscape: from AI-assisted #phishing to self-replicating "worms." www.csoonline.com/article/4081...
csoonline.com
Modern supply-chain attacks and their real-world impact
Supply-chain attacks have evolved considerably in the las two years going from dependency confusion or stolen SSL among others once common attacks to AI-backed social engineering and open-source regis...
000
Ax Sharma @axsharma.com · 14/10/2025
Cybersecurity firm FuzzingLabs has accused Y Combinator-backed Gecko Security of "stealing" its vulnerability disclosures and back-dating blog posts. Gecko has denied wrongdoing. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Security firms debate CVE credit in overlapping vulnerability reports
FuzzingLabs has accused the YCombinator-backed startup, Gecko Security, of replicating its vulnerability disclosures. Gecko allegedly filed for 2 CVEs based on FuzzingLabs' reports without crediting t...
020
Ax Sharma @axsharma.com · 05/10/2025
TLDR: Claim your dollar, beware of phishing attempts. And, lawyers be getting rich. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
ParkMobile pays... $1 each for 2021 data breach that hit 22 million
ParkMobile has finally wrapped up a class action lawsuit over the platform's 2021 data breach that hit 22 million users. But there's a catch: victims are receiving compensation in the form of a $1 in-...
010
Ax Sharma @axsharma.com · 23/09/2025
We’ve seen QR codes in scams before, but those relied on people scanning them. @socket.dev's new discovery shows malware using QR codes to talk to its C2 server — traffic that to security tools looks like harmless image exchanges. www.bleepingcomputer.com/news/securit... #malware #opensource #npm
bleepingcomputer.com
NPM package caught using QR Code to fetch cookie-stealing malware
Newly discovered npm package 'fezbox' employs QR codes to hide a second-stage payload to steal cookies from a user's web browser. The package, masquerading as a utility library, leverages this innovat...
062
Ax Sharma @axsharma.com · 16/09/2025
Self-propagating supply chain attack on 187 npm projects also hit CrowdStrike's namespace. Statement from CrowdStrike 👇 www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Self-propagating supply chain attack hits 187 npm packages
Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the comprom...
020
Reposted by Ax Sharma
BleepingComputer @bleepingcomputer.com · 02/09/2025
Google has disputed a widely reported story about the company warning all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts.
bleepingcomputer.com
No, Google did not warn 2.5 billion Gmail users to reset passwords
Google has disputed a widely reported story about the company warning all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts.
1116
Ax Sharma @axsharma.com · 14/08/2025
Booking[.]com phishing campaign uses sneaky 'ん' character, which can look like '/~' in some fonts, to trick you and deliver #malware. Another creative use of homoglyphs by threat actors. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Booking.com phishing campaign uses sneaky 'ん' character to trick you
Threat actors are leveraging a Unicode character to make phishing links appear like legitimate Booking.com links in a new campaign distributing malware. The attack makes use of the Japanese hiragana c...
120
Reposted by Ax Sharma
Graham Cluley @grahamcluley.com · 12/08/2025
Law enforcement has delivered a $1 million-sized headache to a Russian ransomware gang. BlackSuit (formerly "Royal") has been tormenting over 450 US organisations across critical sectors such as healthcare, education, public safety, energy, manufacturing, and government.
bitdefender.com
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang
The United States Department of Justice has revealed that the recent takedown of the BlackSuit ransomware gang's servers, domains, and dark web extortion site, also saw the seizure of US $1,091,4...
262
Ax Sharma @axsharma.com · 06/08/2025
Looking like a busy Wednesday for National Bank www.bleepingcomputer.com/news/technol...
bleepingcomputer.com
National Bank of Canada online systems down due to 'technical issue'
National Bank of Canada (Banque Nationale du Canada), the sixth largest commercial bank of Canada is currently experiencing a widespread service outage affecting its online banking and mobile app plat...
010
Ax Sharma @axsharma.com · 23/07/2025
npm has "accidentally" taken down all versions of the legitimate Stylus library and replaced them with a "security holding" page, breaking pipelines and builds worldwide. bleepingcomputer.com/news/securit... #opensource #supplychain #javascript
bleepingcomputer.com
npm 'accidentally' removes Stylus package, breaks builds and pipelines
npm has taken down all versions of the Stylus library and replaced them with a "security holding" page, breaking pipelines and builds worldwide that rely on the package.
111
Reposted by Ax Sharma
Zack Whittaker @zackwhittaker.com · 21/07/2025
New, by me: Scott Zuckerman, a spyware founder who was banned from the surveillance industry by the FTC after one of his spyware companies had a data breach, now wants the FTC to *unban* him. Zuckerman claims the cybersecurity requirements put on him after the breach are an "unnecessary burden."
techcrunch.com
Serial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry | TechCrunch
The spyware maker was banned from the surveillance industry in 2021, but was caught flouting the ban less than a year later. Now the founder wants the ban lifted altogether.
03723
Ax Sharma @axsharma.com · 28/06/2025
🎞️ All day: Exposing cybercrime and the latest hacks targeting real people for Rip-Off Britain @ BBC Studios, MediaCityUK.
000