Cybersecurity3 min reading time

'Generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems': Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks

TechRadar
Read full post
Amazon Threat Intelligence has linked a North Korean hacking group to multiple recent compromises of popular NPM software libraries, including axios, debug, chalk, and typo-crypto. The group used social engineering to manipulate trusted maintainers and distribute malicious updates, exploiting generative AI to create convincing malware and evade detection. These attacks have impacted millions of developers and cloud environments by infiltrating widely used open source packages.

More in Cybersecurity

Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 2 sources

Chinese AI Giants Accused of Sending Millions of User Queries to U.S. Models

The Wall Street Journal