Supply Chain

AI Security Daily Briefing — December 9, 2025

In the last 24 hours, Google introduced layered defenses in Chrome to contain indirect prompt injection against its agentic AI features, the UK’s NCSC warned that LLMs will always be vulnerable to prompt injection, and new research revealed malicious VS Code extensions and AI-branded packages stealing developer data and credentials from high-value engineering environments.

AI Security Daily Briefing — October 22, 2025

In the last 24 hours: Oracle’s October CPU ships 374 fixes (many unauth RCEs); Pwn2Own Ireland logs 34 new zero-days on Day 1; CISA flags Windows SMB Client and Kentico bugs as exploited; and a high-severity Rust async-tar flaw (“TARmageddon”) emerges. Plus, the U.N. readies a global cybercrime pact for signature.