Your AI Agent Shouldn't Know Your API Keys
OneCLI, an Apache-2.0 open-source project, introduces a proxy-based architecture that keeps real API keys out of AI agent environments, preventing credential theft even if the agent is prompt-injected…
OneCLI, an Apache-2.0 open-source project, introduces a proxy-based architecture that keeps real API keys out of AI agent environments, preventing credential theft even if the agent is prompt-injected…
OneCLI, a Rust-based Docker container, acts as a network gateway to manage AI agent secrets by swapping placeholders for real credentials at the network layer, preventing agents from directly accessin…
The jscrambler npm package was backdoored five times in three hours on July 11, 2026, after a threat actor stole an npm publishing credential. The malicious versions (8.14.0–8.20.0, excluding 8.15.0) …
A malicious version of the npm package jscrambler used a preinstall hook to deploy a Rust infostealer on developer machines. The attack targeted browser credentials, crypto wallets, and Bitwarden vaul…
A developer known as @projectnomad outlines a five-step credential handoff process for freelance client projects to prevent API keys, database passwords, and hosting logins from being exposed in Slack…
A researcher built a bidirectional command-and-control channel using Bitwarden's icon proxy, embedding commands in PNG metadata and exfiltrating data via DNS to trusted Azure infrastructure. The attac…
A developer created a systemd user service to bridge Bitwarden Desktop's SSH agent from Windows to WSL2 using socat and npiperelay, solving hanging issues with ssh-add. The solution requires the stand…
Hackers are increasingly exploiting trusted developer tools rather than breaking into systems, with two major campaigns this week highlighting the trend. TeamPCP injected malicious code into over 1,00…
A developer studying AI and big data warns that AI is increasing cyber vulnerability in two ways: attackers using AI for more sophisticated attacks, and vulnerabilities introduced by integrating AI in…
A developer forked Bitwarden's browser extension to create Saigon Safe, adding one-click account creation, Touch ID unlock, hidden accounts, and UX improvements while using Bitwarden's backend. The op…
In episode 104 of Pixelated, the hosts discuss Siri integrating Gemini AI, changes to Liquid Glass affecting Android, and other WWDC insights, while Paris Hilton expresses her love for Android and Goo…
A new open-source tool called AVP prevents AI coding agents from leaking API keys by never giving them access to the real secrets. The tool replaces actual credentials with placeholders in the agent's…
The W3C Web Application Security Working Group has standardized the /.well-known/change-password URL as a redirect endpoint that points password managers and users to a site's actual change-password p…
Bitwarden has released security tools to address risks from AI agents accessing company credentials without IT approval, a practice known as "shadow AI." The company warns that unvetted AI agents can …
Bitwarden is likely deteriorating under new CEO, who has a history of gutting companies, following a recent price hike and the quiet removal of its "Always free" commitment. The author advises users t…
Checkmarx, a security firm, has suffered multiple supply-chain attacks over the past 40 days, including two separate malware distribution incidents via its compromised GitHub account and a subsequent …