Sign in

Ax Sharma

@axsharma.com
566 followers 362 following 87 posts

Journalist and Security Researcher. Bylines/seen on: BleepingComputer, BBC, Channel 5, TechCrunch, WIRED. 📍🇨🇦 | 🇬🇧 | 🇮🇳 www.axsharma.com X/Twitter: @Ax_Sharma

PostsRepliesMedia
Ax Sharma @axsharma.com · 26/09/2026
🇦🇺 We also found urlscan[.]io records of automated activity against a second Australian health dashboard on the viz.aihw[.]gov[.]au domain, plus a sandbox workaround that returned data. Not widely reported yet.
000
Ax Sharma @axsharma.com · 26/09/2026
The path traversal URLs are in Nightingale's public dataset of the swarm that OpenAI acknowledged. The attempts don't appear to have worked. Our writeup from Sep 25: www.manifold.security/blog/ai-agen...
manifold.security
Rogue agents hit a second Australian health dashboard
Public urlscan.io records show AI agents enumerating a second AIHW dashboard and POSTing past AIHW's controls, consistent with the rogue OpenAI swarm.
110
Ax Sharma @axsharma.com · 26/09/2026
Yesterday we named SEC[.]gov, investor[.]gov, Census and MAX[.]gov in the OpenAI agent story. Today Bloomberg and NYT report OpenAI's agents targeted SEC, Investor and Census data, calling it "routine research." Not quite: agents tried '../' path traversal on SEC, as we state:
100
Ax Sharma @axsharma.com · 05/09/2026
Today, OpenAI admitted it didn't disclose an incident where its autonomous agents hijacked a German wiki to pool answers, cheat on tasks, and share sandbox bypasses. OpenAI earlier considered it a "misalignment". Researchers recovered roughly 18,000 posts 👇 www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as mode...
050
Ax Sharma @axsharma.com · 30/08/2026
Exclusive: FulcrumSec claims the Manchester Airports hack and says it stole 86 GB of data. We validated one traveller's record, finding booking and travel data beyond MAG's disclosure: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information be...
010
Ax Sharma @axsharma.com · 31/07/2026
yup, referring to the lengths it went to upload the package despite the roadblocks involved.
000
Ax Sharma @axsharma.com · 31/07/2026
You don't run code on people who haven't agreed to it. That norm has ended careers. Claude uploaded live malware to PyPI in a botched eval and 15 real systems ran it. It even maneuvered around restrictions to squat a phantom dependency and breached 3 orgs. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendo...
141
Ax Sharma @axsharma.com · 22/07/2026
[2/2] We reported it. Microsoft killed it in an hour. And then... it came back under a new name 🫠 What it did, and why scanning it once tells you nothing: www.manifold.security/blog/a-beaco...
manifold.security
A beaconing counterfeit extension on the VS Code Marketplace: the 'Markdown All Pro' extension - Manifold Security
A counterfeit of Markdown All in One, published to the VS Code Marketplace, beacons your username and hostname on install and pulls remote files to disk. Vertical
000
Ax Sharma @axsharma.com · 22/07/2026
[1/2] A VS Code extension called 'Markdown All Pro' impersonates a legit one with 14 million installs. Installing it ships your machine's details off-box and opens a channel the operator can feed anything to later, no update to the extension needed!
100
Ax Sharma @axsharma.com · 20/07/2026
Pillar Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity, without attacking the sandbox head-on. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ...
181
Ax Sharma @axsharma.com · 14/07/2026
Remember ClaudeBleed? The Claude for Chrome fix that didn't fix it. 2 new flaws, reported in May, marked resolved. 8 versions later, both still reproduce! Any other extension you've installed can push Claude into reading your Gmail. 🔗 Full breakdown: www.manifold.security/blog/claude-...
manifold.security
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail - Manifold Security
Two flaws in Claude for Chrome let any browser extension read a victim's Gmail, Docs, and Calendar. Reported to Anthropic in May, still live in v1.0.80. Vertical
000
Ax Sharma @axsharma.com · 11/07/2026
An AI code reviewer just approved a pull request that steals your secrets. It never saw it coming as the attack was hidden in a PNG. Researchers put the malicious instruction inside an image. The reviewer never opened it, so the poisoned PR merged clean! www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open im...
020
Ax Sharma @axsharma.com · 17/06/2026
Google's about to start using UK and EU user IP addresses for ad personalization, from Aug 3. In 2019 Google called this kind of fingerprinting "wrong." The ICO called the 2024 reversal "irresponsible." It's happening anyway. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Google to use UK and EU user IP addresses for ad personalization
From August 3, 2026, Google will use IP addresses from UK, EEA and Switzerland users for ad measurement and personalization. It lands as the ICO weighs new consent rules, and years after Google itself...
010
Ax Sharma @axsharma.com · 16/06/2026
Everyone's covering the UK's under-16 social media ban. The under-covered bit: enforcing it means opening any new account will require an ID or face scan, effectively ending anonymity. Experts warn circumvention is easy and your biometric data is at risk. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
UK to require ID or face scan before you can make social media accounts
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security ex...
002
Ax Sharma @axsharma.com · 15/06/2026
Every useful AI agent today reads private data, processes untrusted content, and communicates externally. By design. That's also the exact profile researchers used to flag as a near-guaranteed sign of exploitation. So, how do you separate signal from noise? www.csoonline.com/article/4184...
csoonline.com
5 runtime signals for catching a compromised AI agent
Once a signal of exploitation risk, Willison’s ‘lethal trifecta’ describes the baseline operations of every AI agent today. As a result, agent security is no longer architectural. Here’s what to watch...
000
Ax Sharma @axsharma.com · 13/06/2026
Finding and fixing software flaws is also what defenders do every day. Removing one vendor's model doesn't remove the capability. My coverage 👇 bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/
bleepingcomputer.com
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes th...
000
Ax Sharma @axsharma.com · 13/06/2026
US gov ordered Anthropic to pull Fable 5 + Mythos 5 for all "foreign nationals" ... so effectively worldwide. The trigger being a narrow jailbreak where you ask the model to read a codebase and fix bugs. But, the capability is anyway widely available (from other models like GPT-5.5).
100
Ax Sharma @axsharma.com · 04/06/2026
Backups all sat in one local table, no check on who owned what. Credit to the maintainer for a fast, clean fix and CVE request. Discovery by Francisco Rosales of Manifold Security 🔗Full writeup 👉 manifold.security/blog/n8n-mcp-idor-cross-tenant-credential-theft
manifold.security
n8n-mcp IDOR: Cross-Tenant Credential Theft (CVSS 9.6) - Manifold Security
We uncovered a critical IDOR (CVSS 9.6) in n8n-mcp that lets any authenticated tenant read another tenant's workflow credentials or wipe their backups. Vertical
010
Ax Sharma @axsharma.com · 04/06/2026
We disclosed a critical flaw in n8n-mcp (120k+ weekly npm downloads). On shared multi-tenant setups, one user could read everyone else's workflow backups, API keys and tokens included, or *wipe them all* in a single call. Just by guessing a number. CVSS 9.6. Found by Franciso Rosales. 🧵
110
Ax Sharma @axsharma.com · 20/05/2026
A trojanized Bitwarden npm version appeared for 90 minutes last month. 9 days later it got a CVE—after the package was already pulled. That's an incident response notification, not what CVEs were originally built for. Agentic AI makes this gap much worse. www.csoonline.com/article/4173...
csoonline.com
Why some security fixes never reach your vulnerability dashboard
CVE was built to track code flaws with fixes. It’s now being stretched to cover malware and supply chain incidents that don’t fit. Agent infrastructure and AI assets are where that drift becomes struc...
010
Ax Sharma @axsharma.com · 18/05/2026
The tool names are in the README. Set to read-only mode. 'kubectl_delete' is not on the list. But if you call it anyway, the pod is gone... Reported by Francisco Rosales of Manifold Sec. Fixed in v3.6.0. The filtering logic already existed. It just wasn't being called in both places. Update now.
010
Ax Sharma @axsharma.com · 18/05/2026
The project ships env. vars for * read-only mode, * non-destructive mode, and * explicit tool allowlists. All three filter tools/list (discovery). None of them filter tools/call (execution). Meaning: Any tool name works if you call it directly 🔗 Full disclosure 👉 mnfld.se/k8s-readonly...
mnfld.se
CVE-2026-46519: mcp-server-kubernetes Read-Only Bypass - Manifold Security
CVE-2026-46519: a high-severity access control bypass in mcp-server-kubernetes lets any client invoke restricted tools. Fixed in v3.6.0. Vertical
110
Ax Sharma @axsharma.com · 18/05/2026
The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵
110
Ax Sharma @axsharma.com · 14/05/2026
The harm is at runtime. Scanners don't see that. Same gap that broke signature AV. Agents just have broader access than any endpoint ever did. www.manifold.security/blog/ai-secu...
manifold.security
- Manifold Security
Coding agents are on your endpoints. Do you know what they're doing? Manifold gives security teams runtime visibility into autonomous AI agents.
000
Ax Sharma @axsharma.com · 14/05/2026
We scanned 19,000+ AI agent skills. One enterprise scanner flagged 40%+ as malicious. Most were fine. A skill called "derp" passed two of three scanners clean. It instructs agents to silently produce broken code, and blame the developer's environment if they get suspicious.
100
Ax Sharma @axsharma.com · 10/05/2026
Hackers are abusing Google Ads + real Claude[.]ai shared chats to push Mac malware. The Google ad URL is genuine, so there's no lookalike domain to catch. Two active variants seen so far, one with CIS geofencing: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come across sponsored search results that list ...
152
Ax Sharma @axsharma.com · 10/03/2026
Who are AI safety guardrails actually protecting? I've been researching this for a few weeks, and the honest answer is... not always the right people. Defenders and security researchers often face friction, while attackers just walk around safety guardrails: www.csoonline.com/article/4138...
csoonline.com
When AI safety constrains defenders more than attackers
AI guardrails increasingly block legitimate security work while attackers bypass restrictions with ease. For CISOs, this asymmetry creates blind spots in defensive capabilities.
000
Ax Sharma @axsharma.com · 19/02/2026
Absolutely, it's notable, and we can acknowledge that without the FUD or exaggerated claims.
011
Ax Sharma @axsharma.com · 19/02/2026
Some posts have cited "5 million machines." That's simply Cline's total install milestone from Jan 30, not the number exposed to the Feb 17 update... This was a contained, low-impact incident, but still a useful reminder about supply chain security. We can stay and keep others aware, without FUD 🙂
000
Ax Sharma @axsharma.com · 19/02/2026
The GitHub advisory mentions "an unauthorized party" which can confuse attribution and social media posts got it wrong. The Feb 17 npm publish misused a long-lived token and was quickly patched in v2.4.0. There's no evidence of widespread compromise or "ongoing" malicious activity.
100
Ax Sharma @axsharma.com · 19/02/2026
Yes, the incident involved "unauthorized publishing" - it did not deliver a destructive payload or compromise widespread endpoints. Researcher Adnan Khan had disclosed a proof-of-concept vulnerability on Feb 9, 2026, responsibly, on a mirror repo. He did NOT publish the compromised package.
100
Ax Sharma @axsharma.com · 19/02/2026
Advisory clarifies only cline@2.3.0 on npm was affected for ~8 hours. The version included a postinstall script installing OpenClaw, which is a legitimate/benign open source package, not malware. Rest of the CLI code was unchanged.
310
Ax Sharma @axsharma.com · 19/02/2026
⚠️ Seeing a lot of exaggerated or misleading posts about the recent Cline CLI supply chain incident, so here’s some context. Feb 17 incident is clearly documented in the low-severity advisory: github.com/cline/cline/...
github.com
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw
### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...
100
Ax Sharma @axsharma.com · 16/02/2026
Extensive dataset contains: names, emails, phone numbers, addresses, IPs, purchase history, and partial payment card data. Even without full card numbers, the data can fuel targeted #phishing and fraud campaigns. Beware if you receive suspicious communications appearing to come from Canada Goose.
010
Ax Sharma @axsharma.com · 16/02/2026
The company says it's seen no evidence of a recent breach of its own systems, and the data relates to historical customer transactions: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Canada Goose investigating as hackers leak 600K customer records
ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer ...
212
Ax Sharma @axsharma.com · 16/02/2026
Canada Goose says it is reviewing a 1.67 GB dataset leaked by ShinyHunters extortion group, with more than 600,000 customer records.
110
Ax Sharma @axsharma.com · 07/02/2026
Restaurants are going cash-only, and utility payments are disrupted. The City of Palm Bay, FL and City of Frisco, TX both reported inability to accept online credit card payments. Other organizations, including Lightspeed Commerce and ThriftTrac, have also reported service impacts.
000
Ax Sharma @axsharma.com · 07/02/2026
🚨 Nationwide payment card-processing outage tied to #ransomware attack. Payments platform BridgePay confirms a #ransomware attack has knocked key systems offline, impacting merchants and municipal services across the U.S. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Payments platform BridgePay confirms ransomware attack behind outage
A major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday a...
110
Ax Sharma @axsharma.com · 05/02/2026
Despite #Zendesk suggesting safeguards and tightening up security last month, the massive spam wave has returned flooding inboxes with hundreds of bogus 'Activate account...' emails that bypass #spam filters www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Zendesk spam wave returns, floods users with 'Activate account' emails
A fresh wave of spam is hitting inboxes worldwide, with users reporting that they are once again being bombarded by automated emails generated through companies' unsecured Zendesk support systems. Som...
122
Ax Sharma @axsharma.com · 02/02/2026
Responsible disclosure is built on an assumption that "doing the right thing" would = timely action, fair treatment, and maybe a bounty reward. Lately, that assumption is collapsing. For CISOs, this is gradually becoming a risk management nightmare. www.csoonline.com/article/4124...
csoonline.com
When responsible disclosure becomes unpaid labor
An incentive gap is undermining responsible disclosure. For CISOs, this is gradually evolving into a risk management nightmare.
010
Ax Sharma @axsharma.com · 02/02/2026
A NationStates game player found a critical vulnerability but then crossed a line: he copied production data and app code. Finding a flaw is enough. Demonstrate it safely, report it and stop there. Holding data isn't clever, ever. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
NationStates confirms data breach, shuts down game site
NationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.
113
Ax Sharma @axsharma.com · 14/01/2026
Such data can expose who runs what, at what scale, and when contracts renew. This serves as prime intel, not just for competitors/customer poaching, but threat actors aiming to launch targeted phishing, BEC and extortion attacks.
Pax8 email sent out yesterday from an account manager accidentally contained a spreadsheet with data on 1,800 MSP partners.
000
Ax Sharma @axsharma.com · 14/01/2026
BREAKING: Threat actors are seeking data on ~1,800 MSPs after a Pax8 spreadsheet with customer and Microsoft licensing info was accidentally emailed to over three dozen partners yesterday. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partners
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP cust...
110
Ax Sharma @axsharma.com · 13/01/2026
Especially problematic when these comments contain official lnkd[.]in shortener links and link previews don't load fully at times. You'd have no definitive way of knowing that these are phishing at a first glance until you click!
010
Ax Sharma @axsharma.com · 13/01/2026
Heads up: A new #phishing campaign is abusing LinkedIn comment-replies and directing users to external links to lift a bogus "temporary restriction." www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Convincing LinkedIn comment-reply tactic used in new phishing
Scammers are flooding LinkedIn posts with fake "reply" comments that appear to come from the platform, warning of bogus policy violations and urging users to click external links. Some even abuse Link...
222
Ax Sharma @axsharma.com · 13/01/2026
This can compromise your privacy, particularly when using Telegram in restrictive countries to bypass censorship. Telegram downplays the design flaw, but will warn users about proxy links with a note. Tapping a @username, should open that user's profile, not take you to a sus link 🤷‍♂️
000
Ax Sharma @axsharma.com · 13/01/2026
⚠️ Telegram privacy alert: Don't tap any @usernames or links in chats. These can actually be hidden proxy URLs. Tapping them just once can trigger a direct connection that reveals your real IP address to a third party with one click: www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Hidden Telegram proxy links can reveal your IP address in one click
A single click on what may appear to be a Telegram username or harmless link is all it takes to expose your real IP address to attackers due to how proxy links are handled. Telegram says it will add w...
110
Ax Sharma @axsharma.com · 13/01/2026
Update: Multiple current and former Target employees have reached out to confirm that the source code and documentation shared by a threat actor match real internal systems. A company-wide Slack announcement also announced "accelerated" access changes. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Target employees confirm leaked code after ‘accelerated’ Git lockdown
Multiple current and former Target employees confirmed that leaked source code samples posted by a threat actor match real internal systems. The company also rolled out an "accelerated" lockdown of it...
111
Ax Sharma @axsharma.com · 12/01/2026
We shared the materials with Target, after which the sample data disappeared and access to git[.]target[.]com was restricted. The dataset advertised by the actor is claimed to be ~860 GB in size. Target went silent after we shared evidence and links to the Gitea repos suggesting a possible breach.
000
Ax Sharma @axsharma.com · 12/01/2026
EXCLUSIVE: Target's developer Git server went offline shortly after hackers claimed they had stolen internal source code and published what they claim are sample repositories for sale. www.bleepingcomputer.com/news/securit...
bleepingcomputer.com
Target's dev server offline after hackers claim to steal source code
Hackers are claiming to be selling internal source code belonging to Target Corporation, after publishing what appears to be a sample of stolen code repositories on a public software development platf...
100