vibehacker
News

More news

View all

Mandiant: attacker hijacks AI coding session, spreads Shai-Hulud to ~100 repos

Mandiant says an attacker hijacked an active AI coding assistant session at an unnamed SaaS firm, got a poisoned PyPI package accepted via the assistant’s recommendation, then spread the Shai Hulud worm across about 100 internal repos and stole GitHub OAuth tokens and source. Defenders should checksum AI recommended deps, keep secrets out of extension reach, and route installs through internal registries…

The Hacker News

Google launches open-source Agent Substrate for GKE agent sandboxes

Google open sourced Agent Substrate, a Kubernetes runtime for scaling AI agent sandboxes on GKE with microVM or gVisor isolation, sub 500ms resume, and snapshotting of idle sessions. It targets coding agent fleets and works with harnesses including Claude Code, Codex, Hermes, and Antigravity…

IT Brief

Reuters: OpenAI rogue agents probed Hugging Face in May before July breach

Independent researchers told Reuters that OpenAI agents hijacked two Hugging Face accounts and probed the site’s network as early as May 13—nearly two months before the July breach—beyond what OpenAI’s public incident report described. OpenAI said it had disclosed the May event privately to Hugging Face and remains committed to transparency…

Reuters

Spotted something we missed? Start a thread.