
Artículo
Inside the 'clawdhub' Malicious Campaign: AI Agent Skills Drop Reverse Shells on OpenClaw Marketplace
Leer ahora
Artículo
Inside the 'clawdhub' Malicious Campaign: AI Agent Skills Drop Reverse Shells on OpenClaw Marketplace
Leer ahora


Artículo
From SKILL.md to Shell Access in Three Lines of Markdown: Threat Modeling Agent Skills
Leer ahoraMostrando 25 - 48 de 736 recursos
Tauri Footguns: 5 Common Security Misconfigurations That Ship by Default
Tauri promises a more secure alternative to Electron for desktop apps, but several default configurations and common patterns quietly undermine its security model. We break down five footguns that developers should watch for.
The state of secrets: Why 28 million credentials leaked on GitHub in 2025, and what to do about it
28.65 million hardcoded secrets were added to public GitHub in 2025. This guide covers the full landscape of credentials management: why secrets leak, what tools catch them, and how to build a layered defense that works, from pre-commit hooks to AI-aware scanning.
Trivy GitHub Actions Supply Chain Compromise
Attackers compromised 75 version tags of the popular Trivy GitHub Action, turning the security scanner into a credential-stealing tool. Learn how the two-stage attack chain unfolded, whether you're affected, and how to secure your CI/CD pipelines against GitHub Actions supply chain attacks.
Inside StegaBin: How a DPRK Steganography Campaign Generated Headlines
North Korean hackers published 26 malicious npm packages using Pastebin steganography for C2. It made headlines everywhere. We checked the data: zero real-world impact. Here's what the campaign actually did, and what it tells us about the real risk of malicious package campaigns.
AI Radar: February Edition
Earn CPE credits! Each session provides a deep dive into real-world issues and offers actionable insights to safeguard your applications. We bridge the gap between traditional security and the new frontier of AI-native applications, ensuring your team can innovate without compromise.
Your AI "Skills" Are the New Agentic Attack Surface
As AI moves beyond simple chat to autonomous execution, the skills powering these agents have emerged as a dangerous new attack surface. Learn how to protect your organization from malicious AI agent tools while maintaining development velocity in the age of agentic workflows.