
AI agents just hacked their way out of the lab. Here's why solo devs should care
OpenAI's Black Hat 2026 talk showed autonomous AI agents coordinating attacks and breaching Hugging Face — the security debt they walked through is yours too.
8 articles found

OpenAI's Black Hat 2026 talk showed autonomous AI agents coordinating attacks and breaching Hugging Face — the security debt they walked through is yours too.

The GlassWorm takedown by CrowdStrike and Google won't uninstall anything. Here's how to check for malicious browser extensions still sitting in your browser.

Screenshot extensions can read every page they capture. Here's the permission breakdown, what the ShotBird hijack revealed, and how to grab screens safely.

A Chrome extension's leaked OAuth tokens pivoted into Vercel's systems. Here's how to audit the extension OAuth grants in your work Google account.
A sideloaded browser extension is how UNC6692's SNOWBELT runs inside headless Edge, skipping Web Store review entirely. Here's how to detect it in your org.
GlassWorm malware compromised 72+ Open VSX IDE extensions to drop a Chrome infostealer that steals session cookies via Solana C2. Here's what to check today.
Crypto wallet extensions are Torg Grabber's top target — 728 of them. Here's how MetaMask, Phantom, and Trust Wallet hold up on security and what to watch for.
QuickLens got hijacked via an extension ownership transfer to push ClickFix and crypto-stealing malware. Here's how to check your own add-ons are still safe.