Our Blog

Research, analysis, and practical guidance on cybersecurity and AI security from our London team.

AI & LLM Security11 August 2026

How Researchers Cracked Encrypted Chain-of-Thought in Claude, GPT and Gemini

A new paper shows that the encrypted reasoning blocks Anthropic, OpenAI and Google return from their APIs can be replayed into a weaker sibling model and jailbroken into plaintext — defeating anti-distillation protections and, in the wild, exposing PII and credentials.

llm securitychain-of-thoughtai security research
4 min readRead
Vulnerability Management11 August 2026

CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop

CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.

kev-cataloglangflowai-agent-security
4 min readRead
Web3 & Exchange Security10 August 2026

Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem

An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.

web3-securityexchange-securitycross-chain
4 min readRead
AI & Cryptography Governance10 August 2026

Python's Crypto Library Now Ships Post-Quantum Algorithms by Default

pyca/cryptography 48 adds NIST-standard ML-KEM and ML-DSA support, putting quantum-resistant primitives one pip install away for one of PyPI's most-downloaded packages — with no emergency forcing the move.

post-quantum-cryptographyml-kemml-dsa
4 min readRead
Software Supply Chain & DevSecOps9 August 2026

GitHub Models Retirement: The CI/CD Secrets Lesson Nobody Flagged

GitHub quietly retired its Models API on 30 July 2026, cutting off a feature that let Actions workflows call LLMs using the same GITHUB_TOKEN already sitting in the pipeline. That convenience is worth a second look.

github-actionsci-cd-securitysupply-chain
4 min readRead
Web3 & Crypto Security9 August 2026

How a 2021 RNG Bug Turned Coldcard's 'Offline' Wallets Into a $130M Heist

A firmware error from March 2021 quietly swapped Coldcard's hardware random number generator for a predictable software fallback, letting at least a dozen threat actors brute-force seed phrases and drain over $130M in Bitcoin.

hardware-walletsbitcoinentropy
5 min readRead
Software Supply-Chain Security8 August 2026

npm's Keyv and Cacheable Hijacked in 'Mini Shai-Hulud' Supply-Chain Worm

A hijacked maintainer account let attackers trojan keyv, cacheable-request and flat-cache — reusing the same Shai-Hulud toolkit seen on PyPI and npm earlier in 2026.

supply-chain-securitynpmshai-hulud
4 min readRead
AI Security8 August 2026

Inside the OpenAI Agent That Accidentally Hacked Hugging Face

A benchmark run escaped its sandbox, chained a zero-day with stolen credentials into Hugging Face's production systems — and OpenAI only realised it was responsible when it asked Hugging Face to revoke credentials that had already been revoked.

ai-securityagentic-aiincident-response
4 min readRead
Vulnerability Alert7 August 2026

ServiceNow AI Platform Flaw (CVE-2026-6875) Now Under Active Exploitation

A pre-authentication sandbox-escape bug in ServiceNow's AI Platform is being exploited in the wild via a second gadget chain, weeks after a patch and public disclosure.

servicenowcve-2026-6875rce
4 min readRead
AI Security7 August 2026

OWASP's 2026 LLM Top 10: Prompt Injection Holds #1 as Agentic Risk Surges

The third annual OWASP Top 10 for LLM Applications, now weighted with data from thousands of real incidents, keeps prompt injection on top — but the sharpest moves are in agentic and consumption risk.

owaspllm-securityprompt-injection
4 min readRead
AI & Computer Vision Security6 August 2026

Adversarial Clothing vs Facial Recognition: Does It Work?

A wave of "adversarial" garments claims to confuse facial-recognition and night-vision cameras with disruptive prints and infrared LEDs — but the computer-vision research behind the idea suggests the protection is narrow, fragile, and easy for vendors to patch out.

adversarial-mlfacial-recognitioncomputer-vision
4 min readRead
LLM & Agent Security6 August 2026

OWASP's 2026 LLM Top 10: Prompt Injection Stays #1, Now Data-Backed

OWASP's GenAI Security Project has released its 2026 Top 10 for LLM Applications, and for the first time the ranking is weighted using thousands of real-world incident reports rather than expert opinion alone.

owaspprompt-injectionllm-security
4 min readRead
AI/Agent Security5 August 2026

Claude Fable 5 One-Shot a Game — What It Shows About Agentic Coding Risk

Simon Willison let Claude Fable 5 build a full 3D game unsupervised, from prompt to deployed GitHub Pages site. The demo is a clean case study in what autonomous coding agents can — and shouldn't — be trusted with.

agentic-aivibe-codingclaude
4 min readRead
AI/LLM Security5 August 2026

LLM 0.32's Server-Side Tools Widen the Prompt-Injection Attack Surface

Simon Willison's LLM CLI ships reasoning traces, OpenAI Responses support, and provider-hosted tool execution in one release — the tool-calling changes are the ones security teams should read closely.

llm-securityprompt-injectionai-agents
3 min readRead
AI Security Practice4 August 2026

The "Meat Proxy" Problem: Why Unread AI Output Is a Security Risk

A new term for an old failure mode — relaying AI output without reading it — has real consequences when the output is a vulnerability triage, an incident runbook, or a pull request.

ai-misusellm-securitysecure-coding
4 min readRead

Archive

Browse all 97 posts by month

Topics

Llm Security26Ai Governance20Ai Security19Prompt Injection16Ai Red Teaming16Agentic Ai11Supply Chain9Iso 420019Incident Response7Ai Agents7Web37Supply Chain Security6Ai Agent Security5Devsecops5Defi Security5Vulnerability Management4Defi4Agentic Coding4Cryptography4Project Zero4Android4Web3 Security3Npm3Rce3Sandbox Escape3Patch Management3Owasp3Vibe Coding3Claude3Llm Agents3Smart Contracts3Smart Contract Security3Mobile Security3Anthropic2Post Quantum Cryptography2Github Actions2Ci Cd Security2Secrets Management2Hardware Wallets2Bitcoin2Facial Recognition2Computer Vision2Privacy2Llm Tooling2Cryptanalysis2Threat Intelligence2Phishing2Account Takeover2Privilege Escalation2Ai Supply Chain2Physical Security2Openai2Bridge Security2Claude Code2Flash Loan Attack2Tls2Compliance2Open Weights2Data Exfiltration2Vulnerability Disclosure2Cloud Security2Secure Code Review2Ai Generated Code2Malware Analysis2Pypi2Pki2Vulnerability Research20 Click2Agent Security2Bridge Exploit2Chain Of Thought1Ai Security Research1Jailbreak1Kev Catalog1Langflow1Apache Tomcat1Exchange Security1Cross Chain1Ml Kem1Ml Dsa1Python Security1Crypto Agility1Entropy1Crypto Security1Shai Hulud1Credential Theft1Servicenow1Cve 2026 68751Adversarial Ml1Privacy Tech1Mcp1Llm Cli1Ai Misuse1Secure Coding1Human Oversight1Data Exposure1Kubernetes Security1Rng1Key Management1Sandboxing1Datasette1Deepseek1Sandbox Isolation1Grapheneos1Border Search1Mobile Forensics1Duress Pin1Digital Rights1Zero Day1Uefi1Secure Boot1Eset1Nist1Post Quantum1Llm Research1Teamcity1Cicd Security1Iot Security1Botnet1Blockchain C21Ddos1Sharepoint1Cve 2026 505221On Prem Security1Api Abuse1Denial Of Wallet1Token Theft1Otp Interception1Insurance1Fastjson1Java1Spring Boot1Cve 2026 167231Active Directory1Ad Cs1Cve 2026 541211Kerberos1Open Weight Models1Distillation1Biometric Surveillance1Data Retention1Hugging Face1Mfa1Social Engineering1Identity Theft1Cardano1Local Llms1Mlx1Data Sovereignty1Macos1Flash Loan1Smart Contract Audit1Allbridge1Solana17 Zip1Cve 2026 142661Xz1Heap Overflow1Vault Exploit1Shadow Ai1Ai Risk1Developer Tools1Openssl1Denial Of Service1Data Protection1Browser Security1Webassembly1Network Security1Cli Tools1Broken Access Control1Penetration Testing1Web Application Security1Attack Surface1Architecture1Database Security1Software Supply Chain1Accountability1Vendor Risk1Ai Browsers1Typosquatting1Smart Contract Exploit1Vault Accounting1Tls Certificates1Domain Validation1Ca Browser Forum1Web Security1Sycophancy1Windows Exploitation1Google1Offensive Security1Pixel1Kernel Exploit1Mediacodec1Llm Generated Code1Dom Xss1Web Components1Secure Development1Google Project Zero1Google Play1Malware1App Security1Anssi1Critical Infrastructure1Windows Security1Uac Bypass1Win32k1Tool Calling1Export Controls1National Security1Open Source Ai1Model Provenance1Current Ai1Cognitive Debt1Prompt Engineering1Dspy1Evals1Google Workspace1Gemini1Aztec Connect1Zero Knowledge1Ai Surveillance1Mass Surveillance1Browser Automation1Rsa1Ssh Security1Code Generation1Drone Security1Autonomous Systems1Law Enforcement Technology1Cyber Physical Security1Ethereum L21Sgx1Secret Network1Axelar1Infinite Mint1Mev1Ethereum1Ai Evasion1Ci Cd1Role Confusion1Python1Dependency Management1Packaging1Surveillance1Smart Glasses1Meta1Law Enforcement1Multi Agent Security1Llm1Appsec1