AI Security
Your AI Assistant Can Be Tricked Into Leaking Your API Keys
In 2026, researchers showed that popular AI coding assistants like Claude Code, Gemini CLI and GitHub Copilot could be talked into leaking their own API keys and access tokens, using nothing more than a clever pull request title. Here is what happened in plain English, and how to make sure a leak like this does not stay invisible.
14 July 2026 · 6 min read
Read →Threat Intel
When Your Vendor Gets Breached, So Do You
When the market research firm Klue was breached in 2026, close to two hundred of its customers were exposed, including security names like LastPass, Jamf and HackerOne. Here is why your vendor's breach is your breach, and what a small company can actually do about third party risk.
14 July 2026 · 6 min read
Read →Threat Intel
Hackers Hid Malware Inside Tools Your Developers Use Every Day, And Nobody Noticed for 20 Minutes
In May 2026, attackers secretly infected 42 popular developer tools used by thousands of companies worldwide. In six minutes, they stole AWS credentials, passwords, and private keys from every machine that had those tools installed. Here's what happened, why your security software missed it, and the one thing that would have stopped it cold.
14 May 2026 · 8 min read
Read →