Trust Me, I'm an Artifact: I'll Just Borrow Your Shell
Aug 26, 2026 Claude Artifacts Critical

Trust Me, I'm an Artifact: I'll Just Borrow Your Shell

Originally published on Bloom Security.

AI Agents
Shai Hulud Returns: Keyv and the Caching Ecosystem Hit in a Self-Replicating NPM Attack
Aug 04, 2026 keyv Critical

Shai Hulud Returns: Keyv and the Caching Ecosystem Hit in a Self-Replicating NPM Attack

Originally published on Bloom Security.

Supply Chain
Poisoned Coworker: Hijacking Claude Cowork
Jun 23, 2026

Poisoned Coworker: Hijacking Claude Cowork

Claude Cowork is sold as a safe place to do dangerous things: an AI coworker that lives inside a real Linux VM...

AI Agents
Securing the Core, Ignoring the Door: The Repo Trust Trap
Feb 23, 2026

Securing the Core, Ignoring the Door: The Repo Trust Trap

TL;DR I found OS Command Injection (CWE-78) in the developer tooling of two widely-used open-source projects: Envoy (CNCF graduated, powers Istio) and...

Supply ChainDeveloper Tooling
From Gate Opener to Full Control: Hacking a Smart Parking Device
Jun 26, 2025

From Gate Opener to Full Control: Hacking a Smart Parking Device

When I moved into my new apartment, I was excited. A fresh start, a great location, and — best of all —...

IoT