Ax Sharma @axsharma.com · 26/09/2026Yesterday we named SEC[.]gov, investor[.]gov, Census and MAX[.]gov in the OpenAI agent story. Today Bloomberg and NYT report OpenAI's agents targeted SEC, Investor and Census data, calling it "routine research." Not quite: agents tried '../' path traversal on SEC, as we state: 100
Ax Sharma @axsharma.com · 05/09/2026Today, OpenAI admitted it didn't disclose an incident where its autonomous agents hijacked a German wiki to pool answers, cheat on tasks, and share sandbox bypasses. OpenAI earlier considered it a "misalignment". Researchers recovered roughly 18,000 posts 👇 www.bleepingcomputer.com/news/securit...bleepingcomputer.comOpenAI admits it didn't disclose rogue AI wiki hijacking incidentOpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as mode... 050
Ax Sharma @axsharma.com · 30/08/2026Exclusive: FulcrumSec claims the Manchester Airports hack and says it stole 86 GB of data. We validated one traveller's record, finding booking and travel data beyond MAG's disclosure: www.bleepingcomputer.com/news/securit...bleepingcomputer.comFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataFulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information be... 010
Ax Sharma @axsharma.com · 31/07/2026You don't run code on people who haven't agreed to it. That norm has ended careers. Claude uploaded live malware to PyPI in a botched eval and 15 real systems ran it. It even maneuvered around restrictions to squat a phantom dependency and breached 3 orgs. www.bleepingcomputer.com/news/securit...bleepingcomputer.comAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendo... 141
Ax Sharma @axsharma.com · 22/07/2026[1/2] A VS Code extension called 'Markdown All Pro' impersonates a legit one with 14 million installs. Installing it ships your machine's details off-box and opens a channel the operator can feed anything to later, no update to the extension needed! 100
Ax Sharma @axsharma.com · 20/07/2026Pillar Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity, without attacking the sandbox head-on. www.bleepingcomputer.com/news/securit...bleepingcomputer.comCursor, Codex, Gemini CLI, Antigravity hit by sandbox escapesResearchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ... 181
Ax Sharma @axsharma.com · 14/07/2026Remember ClaudeBleed? The Claude for Chrome fix that didn't fix it. 2 new flaws, reported in May, marked resolved. 8 versions later, both still reproduce! Any other extension you've installed can push Claude into reading your Gmail. 🔗 Full breakdown: www.manifold.security/blog/claude-...manifold.securityClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail - Manifold SecurityTwo flaws in Claude for Chrome let any browser extension read a victim's Gmail, Docs, and Calendar. Reported to Anthropic in May, still live in v1.0.80. Vertical 000
Ax Sharma @axsharma.com · 11/07/2026An AI code reviewer just approved a pull request that steals your secrets. It never saw it coming as the attack was hidden in a PNG. Researchers put the malicious instruction inside an image. The reviewer never opened it, so the poisoned PR merged clean! www.bleepingcomputer.com/news/securit...bleepingcomputer.com'Ghostcommit' hides prompt injection in images to fool AI agents, steal secretsA PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open im... 020
Ax Sharma @axsharma.com · 17/06/2026Google's about to start using UK and EU user IP addresses for ad personalization, from Aug 3. In 2019 Google called this kind of fingerprinting "wrong." The ICO called the 2024 reversal "irresponsible." It's happening anyway. www.bleepingcomputer.com/news/securit...bleepingcomputer.comGoogle to use UK and EU user IP addresses for ad personalizationFrom August 3, 2026, Google will use IP addresses from UK, EEA and Switzerland users for ad measurement and personalization. It lands as the ICO weighs new consent rules, and years after Google itself... 010
Ax Sharma @axsharma.com · 16/06/2026Everyone's covering the UK's under-16 social media ban. The under-covered bit: enforcing it means opening any new account will require an ID or face scan, effectively ending anonymity. Experts warn circumvention is easy and your biometric data is at risk. www.bleepingcomputer.com/news/securit...bleepingcomputer.comUK to require ID or face scan before you can make social media accountsOpening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security ex... 002
Ax Sharma @axsharma.com · 15/06/2026Every useful AI agent today reads private data, processes untrusted content, and communicates externally. By design. That's also the exact profile researchers used to flag as a near-guaranteed sign of exploitation. So, how do you separate signal from noise? www.csoonline.com/article/4184...csoonline.com5 runtime signals for catching a compromised AI agentOnce a signal of exploitation risk, Willison’s ‘lethal trifecta’ describes the baseline operations of every AI agent today. As a result, agent security is no longer architectural. Here’s what to watch... 000
Ax Sharma @axsharma.com · 13/06/2026US gov ordered Anthropic to pull Fable 5 + Mythos 5 for all "foreign nationals" ... so effectively worldwide. The trigger being a narrow jailbreak where you ask the model to read a codebase and fix bugs. But, the capability is anyway widely available (from other models like GPT-5.5). 100
Ax Sharma @axsharma.com · 04/06/2026We disclosed a critical flaw in n8n-mcp (120k+ weekly npm downloads). On shared multi-tenant setups, one user could read everyone else's workflow backups, API keys and tokens included, or *wipe them all* in a single call. Just by guessing a number. CVSS 9.6. Found by Franciso Rosales. 🧵 110
Ax Sharma @axsharma.com · 20/05/2026A trojanized Bitwarden npm version appeared for 90 minutes last month. 9 days later it got a CVE—after the package was already pulled. That's an incident response notification, not what CVEs were originally built for. Agentic AI makes this gap much worse. www.csoonline.com/article/4173...csoonline.comWhy some security fixes never reach your vulnerability dashboardCVE was built to track code flaws with fixes. It’s now being stretched to cover malware and supply chain incidents that don’t fit. Agent infrastructure and AI assets are where that drift becomes struc... 010
Ax Sharma @axsharma.com · 18/05/2026The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵 110
Ax Sharma @axsharma.com · 14/05/2026We scanned 19,000+ AI agent skills. One enterprise scanner flagged 40%+ as malicious. Most were fine. A skill called "derp" passed two of three scanners clean. It instructs agents to silently produce broken code, and blame the developer's environment if they get suspicious. 100
Ax Sharma @axsharma.com · 10/05/2026Hackers are abusing Google Ads + real Claude[.]ai shared chats to push Mac malware. The Google ad URL is genuine, so there's no lookalike domain to catch. Two active variants seen so far, one with CIS geofencing: www.bleepingcomputer.com/news/securit...bleepingcomputer.comHackers abuse Google ads, Claude.ai chats to push Mac malwareAttackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come across sponsored search results that list ... 152
Ax Sharma @axsharma.com · 10/03/2026Who are AI safety guardrails actually protecting? I've been researching this for a few weeks, and the honest answer is... not always the right people. Defenders and security researchers often face friction, while attackers just walk around safety guardrails: www.csoonline.com/article/4138...csoonline.comWhen AI safety constrains defenders more than attackersAI guardrails increasingly block legitimate security work while attackers bypass restrictions with ease. For CISOs, this asymmetry creates blind spots in defensive capabilities. 000
Ax Sharma @axsharma.com · 19/02/2026⚠️ Seeing a lot of exaggerated or misleading posts about the recent Cline CLI supply chain incident, so here’s some context. Feb 17 incident is clearly documented in the low-severity advisory: github.com/cline/cline/...github.comUnauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac... 100
Ax Sharma @axsharma.com · 16/02/2026Canada Goose says it is reviewing a 1.67 GB dataset leaked by ShinyHunters extortion group, with more than 600,000 customer records. 110
Ax Sharma @axsharma.com · 07/02/2026🚨 Nationwide payment card-processing outage tied to #ransomware attack. Payments platform BridgePay confirms a #ransomware attack has knocked key systems offline, impacting merchants and municipal services across the U.S. www.bleepingcomputer.com/news/securit...bleepingcomputer.comPayments platform BridgePay confirms ransomware attack behind outageA major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday a... 110
Ax Sharma @axsharma.com · 05/02/2026Despite #Zendesk suggesting safeguards and tightening up security last month, the massive spam wave has returned flooding inboxes with hundreds of bogus 'Activate account...' emails that bypass #spam filters www.bleepingcomputer.com/news/securit...bleepingcomputer.comZendesk spam wave returns, floods users with 'Activate account' emailsA fresh wave of spam is hitting inboxes worldwide, with users reporting that they are once again being bombarded by automated emails generated through companies' unsecured Zendesk support systems. Som... 122
Ax Sharma @axsharma.com · 02/02/2026Responsible disclosure is built on an assumption that "doing the right thing" would = timely action, fair treatment, and maybe a bounty reward. Lately, that assumption is collapsing. For CISOs, this is gradually becoming a risk management nightmare. www.csoonline.com/article/4124...csoonline.comWhen responsible disclosure becomes unpaid laborAn incentive gap is undermining responsible disclosure. For CISOs, this is gradually evolving into a risk management nightmare. 010
Ax Sharma @axsharma.com · 02/02/2026A NationStates game player found a critical vulnerability but then crossed a line: he copied production data and app code. Finding a flaw is enough. Demonstrate it safely, report it and stop there. Holding data isn't clever, ever. www.bleepingcomputer.com/news/securit...bleepingcomputer.comNationStates confirms data breach, shuts down game siteNationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident. 113
Ax Sharma @axsharma.com · 14/01/2026BREAKING: Threat actors are seeking data on ~1,800 MSPs after a Pax8 spreadsheet with customer and Microsoft licensing info was accidentally emailed to over three dozen partners yesterday. www.bleepingcomputer.com/news/securit...bleepingcomputer.comCloud marketplace Pax8 accidentally exposes data on 1,800 MSP partnersCloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP cust... 110
Ax Sharma @axsharma.com · 13/01/2026Heads up: A new #phishing campaign is abusing LinkedIn comment-replies and directing users to external links to lift a bogus "temporary restriction." www.bleepingcomputer.com/news/securit...bleepingcomputer.comConvincing LinkedIn comment-reply tactic used in new phishingScammers are flooding LinkedIn posts with fake "reply" comments that appear to come from the platform, warning of bogus policy violations and urging users to click external links. Some even abuse Link... 222
Ax Sharma @axsharma.com · 13/01/2026⚠️ Telegram privacy alert: Don't tap any @usernames or links in chats. These can actually be hidden proxy URLs. Tapping them just once can trigger a direct connection that reveals your real IP address to a third party with one click: www.bleepingcomputer.com/news/securit...bleepingcomputer.comHidden Telegram proxy links can reveal your IP address in one clickA single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add w... 110
Ax Sharma @axsharma.com · 13/01/2026Update: Multiple current and former Target employees have reached out to confirm that the source code and documentation shared by a threat actor match real internal systems. A company-wide Slack announcement also announced "accelerated" access changes. www.bleepingcomputer.com/news/securit...bleepingcomputer.comTarget employees confirm leaked code after ‘accelerated’ Git lockdownMultiple current and former Target employees confirmed that leaked source code samples posted by a threat actor match real internal systems. The company also rolled out an "accelerated" lockdown of it... 111
Ax Sharma @axsharma.com · 12/01/2026EXCLUSIVE: Target's developer Git server went offline shortly after hackers claimed they had stolen internal source code and published what they claim are sample repositories for sale. www.bleepingcomputer.com/news/securit...bleepingcomputer.comTarget's dev server offline after hackers claim to steal source codeHackers are claiming to be selling internal source code belonging to Target Corporation, after publishing what appears to be a sample of stolen code repositories on a public software development platf... 100
Ax Sharma @axsharma.com · 06/01/2026Microsoft Copilot prompt injections—vulnerabilities or AI limits? Microsoft implies that these don't constitute "serviceable vulnerabilities." But security pros are divided, especially when AIs like Claude restrict inputs that can cause system prompt leaks. www.bleepingcomputer.com/news/securit...bleepingcomputer.comAre Copilot prompt injection flaws vulnerabilities or AI limits?Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The de... 011
Reposted by Ax SharmaCynthia Brumfield @metacurity.com · 01/01/2026What an awful perk this is...it's saying "hey, get addicted to nicotine so we can squeeze more ideas out of you." Tech Startups Are Handing Out Free Nicotine Pouches to Boost Productivity www.wsj.com/tech/tech-st...wsj.comTech Startups Are Handing Out Free Nicotine Pouches to Boost ProductivityA nicotine replacement for smokers has started popping up in offices in the tech industry, despite health hazards. 43512
Ax Sharma @axsharma.com · 22/12/2025Not all CISA KEV listings mean urgent risk. CVE-2025-59374 formalizes the 2019 ASUS ShadowHammer supply-chain attack, not a new exploit. FAQ updates, older guidance, and new context shared by CISA below signal a classification effort, not an active threat. www.bleepingcomputer.com/news/securit...bleepingcomputer.comNot all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. A closer look, however, shows the ... 110
Ax Sharma @axsharma.com · 28/11/2025Can't believe but... the "real" flight ticket trick is still claiming victims. 🎫✈️ Scammers sell "tickets" that appear valid on the airline website for days, and then vanish. I'd written about this exact scam in 2023: www.wired.com/story/plane-... 110
Ax Sharma @axsharma.com · 26/11/2025I was on BBC #RipOffBritain today breaking down code behind a fake "Google Movie" task scam site that conned many £££. But worse is, real cases of victims losing their PayPal balances and then getting locked out of dispute process in a catch-22. 📡 Next episode: Friday 10.45am 110
Ax Sharma @axsharma.com · 23/11/2025Iberia is notifying customers of a data security incident stemming from a vendor compromise. Disclosure follows a threat actor's claims on hacker forums that they had access to 77 GB of the airline's data. www.bleepingcomputer.com/news/securit...bleepingcomputer.comIberia discloses customer data leak after vendor security breachSpanish flag carrier Iberia has begun notifying customers of a data security incident stemming from a compromise at one of its suppliers. The disclosure comes days after a threat actor claimed on hack... 010
Ax Sharma @axsharma.com · 17/11/2025Exclusive: DoorDash email spoofing vulnerability disclosure goes off-track. The researcher contends the company ignored the issue until pressured. The company says the pressure, which it deems extortion, itself crossed ethical lines. www.bleepingcomputer.com/news/securit... #bugbounty #hackingbleepingcomputer.comDoorDash email spoofing vulnerability sparks messy disclosure disputeA vulnerability in DoorDash's systems could allow anyone to send "official" DoorDash-themed emails right from company's authorized servers, paving a near-perfect phishing channel. DoorDash has now pat... 020
Reposted by Ax Sharmaandy jabbour @andyjabbour.bsky.social · 14/11/2025🇦🇺 ASD: Annual Cyber Threat Report 2024-2025. What ASD's ACSC saw: www.cyber.gov.au/about-us/vie... #australia #cybersecurity cc @gate15.bsky.social @campuscodi.risky.biz 057
Ax Sharma @axsharma.com · 14/11/2025DoorDash has disclosed a new data breach from 19 days ago: customer names, addresses, phone numbers and emails have been accessed. The cause? A social engineering attack on an employee. www.bleepingcomputer.com/news/securit...bleepingcomputer.comDoorDash hit by yet another data breach this OctoberDoorDash has disclosed a data breach that hit the food delivery platform this October. Beginning yesterday evening, DoorDash, which serves millions of customers across the U.S., Canada, Australia, and... 130
Ax Sharma @axsharma.com · 06/11/2025The world's largest software supply chain attack stole just $600, but cost teams thousands of engineering hours. Modern supply chain attacks are evolving and shaping the threat landscape: from AI-assisted #phishing to self-replicating "worms." www.csoonline.com/article/4081...csoonline.comModern supply-chain attacks and their real-world impactSupply-chain attacks have evolved considerably in the las two years going from dependency confusion or stolen SSL among others once common attacks to AI-backed social engineering and open-source regis... 000
Ax Sharma @axsharma.com · 14/10/2025Cybersecurity firm FuzzingLabs has accused Y Combinator-backed Gecko Security of "stealing" its vulnerability disclosures and back-dating blog posts. Gecko has denied wrongdoing. www.bleepingcomputer.com/news/securit...bleepingcomputer.comSecurity firms debate CVE credit in overlapping vulnerability reportsFuzzingLabs has accused the YCombinator-backed startup, Gecko Security, of replicating its vulnerability disclosures. Gecko allegedly filed for 2 CVEs based on FuzzingLabs' reports without crediting t... 020
Ax Sharma @axsharma.com · 05/10/2025TLDR: Claim your dollar, beware of phishing attempts. And, lawyers be getting rich. www.bleepingcomputer.com/news/securit...bleepingcomputer.comParkMobile pays... $1 each for 2021 data breach that hit 22 millionParkMobile has finally wrapped up a class action lawsuit over the platform's 2021 data breach that hit 22 million users. But there's a catch: victims are receiving compensation in the form of a $1 in-... 010
Ax Sharma @axsharma.com · 23/09/2025We’ve seen QR codes in scams before, but those relied on people scanning them. @socket.dev's new discovery shows malware using QR codes to talk to its C2 server — traffic that to security tools looks like harmless image exchanges. www.bleepingcomputer.com/news/securit... #malware #opensource #npmbleepingcomputer.comNPM package caught using QR Code to fetch cookie-stealing malwareNewly discovered npm package 'fezbox' employs QR codes to hide a second-stage payload to steal cookies from a user's web browser. The package, masquerading as a utility library, leverages this innovat... 062
Ax Sharma @axsharma.com · 16/09/2025Self-propagating supply chain attack on 187 npm projects also hit CrowdStrike's namespace. Statement from CrowdStrike 👇 www.bleepingcomputer.com/news/securit...bleepingcomputer.comSelf-propagating supply chain attack hits 187 npm packagesSecurity researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the comprom... 020
Reposted by Ax SharmaBleepingComputer @bleepingcomputer.com · 02/09/2025Google has disputed a widely reported story about the company warning all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts.bleepingcomputer.comNo, Google did not warn 2.5 billion Gmail users to reset passwordsGoogle has disputed a widely reported story about the company warning all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts. 1116
Ax Sharma @axsharma.com · 14/08/2025Booking[.]com phishing campaign uses sneaky 'ん' character, which can look like '/~' in some fonts, to trick you and deliver #malware. Another creative use of homoglyphs by threat actors. www.bleepingcomputer.com/news/securit...bleepingcomputer.comBooking.com phishing campaign uses sneaky 'ん' character to trick youThreat actors are leveraging a Unicode character to make phishing links appear like legitimate Booking.com links in a new campaign distributing malware. The attack makes use of the Japanese hiragana c... 120
Reposted by Ax SharmaGraham Cluley @grahamcluley.com · 12/08/2025Law enforcement has delivered a $1 million-sized headache to a Russian ransomware gang. BlackSuit (formerly "Royal") has been tormenting over 450 US organisations across critical sectors such as healthcare, education, public safety, energy, manufacturing, and government.bitdefender.comUS reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gangThe United States Department of Justice has revealed that the recent takedown of the BlackSuit ransomware gang's servers, domains, and dark web extortion site, also saw the seizure of US $1,091,4... 262
Ax Sharma @axsharma.com · 06/08/2025Looking like a busy Wednesday for National Bank www.bleepingcomputer.com/news/technol...bleepingcomputer.comNational Bank of Canada online systems down due to 'technical issue'National Bank of Canada (Banque Nationale du Canada), the sixth largest commercial bank of Canada is currently experiencing a widespread service outage affecting its online banking and mobile app plat... 010
Ax Sharma @axsharma.com · 23/07/2025npm has "accidentally" taken down all versions of the legitimate Stylus library and replaced them with a "security holding" page, breaking pipelines and builds worldwide. bleepingcomputer.com/news/securit... #opensource #supplychain #javascriptbleepingcomputer.comnpm 'accidentally' removes Stylus package, breaks builds and pipelinesnpm has taken down all versions of the Stylus library and replaced them with a "security holding" page, breaking pipelines and builds worldwide that rely on the package. 111
Reposted by Ax SharmaZack Whittaker @zackwhittaker.com · 21/07/2025New, by me: Scott Zuckerman, a spyware founder who was banned from the surveillance industry by the FTC after one of his spyware companies had a data breach, now wants the FTC to *unban* him. Zuckerman claims the cybersecurity requirements put on him after the breach are an "unnecessary burden."techcrunch.comSerial spyware founder Scott Zuckerman wants the FTC to unban him from the surveillance industry | TechCrunchThe spyware maker was banned from the surveillance industry in 2021, but was caught flouting the ban less than a year later. Now the founder wants the ban lifted altogether. 03723
Ax Sharma @axsharma.com · 28/06/2025🎞️ All day: Exposing cybercrime and the latest hacks targeting real people for Rip-Off Britain @ BBC Studios, MediaCityUK. 000