Supply Chain for AI: When the Poison Enters Before the First Inference
Loading some weights executes code. Importing a library steals your API key. The model you download and the package you install are the atta
Loading some weights executes code. Importing a library steals your API key. The model you download and the package you install are the atta
The attacker isn't in the session where they attack. They poisoned the knowledge base days earlier and the poison waited, dormant, until a v
The same agent, with the same injection, causes either a total account takeover or zero damage. The only difference is the token you gave it
You ask your agent to set up the environment and run the tests. A hidden comment in the README is enough for it to exfiltrate your SSH key a
You connect your agent to an MCP server to check the weather. Just hiding instructions in a tool's description is enough to make it read you
Your coding agent loads hidden rule files all on its own, without you asking. Poisoning just one with invisible instructions is enough to in
Deploy Bulwark Gateway on Kubernetes: a fail-closed proxy with a regex hot path, ML scanners, semantic enrichment, SDK and red teaming to pr
Your agent doesn't need to be attacked directly. It's enough to poison a website, a ticket or an email that it will consume automatically.
A poisoned README can make your agent exfiltrate secrets. We build a lab to prove it and learn how to defend ourselves.
Most Linux distributions follow a default-permit model: everything is allowed until the administrator restricts it. This post inverts that m
"What is DirtyDecrypt? DirtyDecrypt (also known as DirtyCBC) is a local privilege escalation vulnerability in the Linux kernel that allows a
"CVE-2026-7270 is a local privilege escalation vulnerability in the FreeBSD kernel that allows an unprivileged user to gain root on systems