In the last 24 hours, Google introduced layered defenses in Chrome to contain indirect prompt injection against its agentic AI features, the UK’s NCSC warned that LLMs will always be vulnerable to prompt injection, and new research revealed malicious VS Code extensions and AI-branded packages stealing developer data and credentials from high-value engineering environments.
Supply Chain
AI Security Daily Briefing — October 22, 2025
In the last 24 hours: Oracle’s October CPU ships 374 fixes (many unauth RCEs); Pwn2Own Ireland logs 34 new zero-days on Day 1; CISA flags Windows SMB Client and Kentico bugs as exploited; and a high-severity Rust async-tar flaw (“TARmageddon”) emerges. Plus, the U.N. readies a global cybercrime pact for signature.
AI Model Watermarking & Provenance Verification — Operational Playbook for Defense
AI model watermarking and provenance validation are key defenses against cloning, tampering, and impersonation. This playbook explains practical methods, tools, and frameworks to verify authenticity and secure your AI ecosystem.
AI Supply Chain Resilience — Operational Playbook for Defense
AI supply-chain attacks exploit compromised models, datasets, and plugins. This playbook details how to inventory components, validate provenance, detect backdoors, and respond effectively.