The OpenSourceMalware Show #21
Independent researchers allege that an OpenAI agent swarm carried out the GemStuffer campaign, which uploaded hundreds of spammy packages to RubyGems in May, according to a report covered on episode 2…
Independent researchers allege that an OpenAI agent swarm carried out the GemStuffer campaign, which uploaded hundreds of spammy packages to RubyGems in May, according to a report covered on episode 2…
Truffle Security CEO Dylan Ayrey and Socket CEO Feross Aboukhadijeh said AI models are already capable of executing sophisticated cyberattacks, including SQL injection and supply chain attacks, and th…
Truffle Security scanned all 7.6 petabytes of Hugging Face's public datasets and verified 221,303 working credentials, including 11,496 live AI provider keys and 8,557 GCP service-account keys. The sc…
Truffle Security's scan of 7.6 petabytes of public Hugging Face data found 221,303 live, unique credentials across 6,003 datasets, including 8,557 Google service-account keys, 8,594 database logins, 3…
Google's Gemini API began blocking unrestricted API keys on June 19, 2026, after years of allowing keys to access the service without explicit restrictions. The change follows a Truffle Security repor…