







TL;DR: It’s a sci-fi riff on Ken Thompson’s “Trusting Trust.” A team finds that its compiler secretly rewrites programs—and itself—so clean source cannot remove the infection. Each workaround teaches the worm to move deeper, until even debuggers, switches and hardware may be lying.
Aug 15, 2026 at 3:20 AM
Reflections on trusting trust
To what extent should one trust a statement that a program is free of Trojan horses? Perhaps it is more important to trust the people who wrote the software.

How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM | Snyk
On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM's CI/CD pipeline. Here's what happened, how the three-stage malware works, and how to check if you're affected.

Snowflake Cortex AI Escapes Sandbox and Executes Malware
PromptArmor report on a prompt injection attack chain in Snowflake's Cortex Agent, now fixed. The attack started when a Cortex user asked the agent to review a GitHub repository that …
Glassworm Returns: Invisible Unicode Malware Found in 150+ GitHub Repositories
The Glassworm supply chain attack is back. Researchers uncovered malware hidden in invisible Unicode characters across 150+ GitHub repositories, plus npm packages and VS Code extensions.

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
Joanna Rutkowska (@rootkovska) on X
Distrusts computers. Keeps embracing them anyway. Previously: Golem Foundation/Wildland, Qubes OS, hardware/virtualization/OS security research.

A GitHub Issue Title Compromised 4,000 Developer Machines
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

Never-before-seen Linux malware is “far more advanced than typical”
VoidLink includes an unusually broad and advanced array of capabilities.

What I Found Interesting in Claude Code's Source
A breakdown of the most interesting engineering patterns in Claude Code's leaked source code: composable system prompts, runtime instruction injection, context compression, forking, prompt caching architecture, and more.
Code Worth Writing - Ray Myers | SSW 2026
Microsoft Struggling With Hundreds of AI-Discovered Security Bugs — ProPublica
Anthropic’s Mythos has flagged bugs faster than Microsoft can fix them. Documents reviewed by ProPublica reveal the tech giant's “mad dash” behind the scenes to patch holes before hackers can find and exploit them.

When compilers surprise you — Matt Godbolt’s blog
Sometimes compilers can surprise and delight even a jaded old engineer like me
This machine kills secrets: how WikiLeakers, cypherpunks and hacktivists aim to free the world's information
The barbarians aren't at the gates. They're inside. Thi…

HACKING – A Hacker Manifesto
The apologists for the vectoral interest want to limit the se- mantic productivity of the term “hacker” to a mere crimi- nality, precisely because they fear its more abstract and multiple potential—its class potential. Everywhere one hears rumors of the hacker as the new form of juvenile delinquent, or nihilist vandal, or servant of organized crime. Or, the hacker is presented as a mere harmless subculture, an obsessive garage pursuit with its restrictive styles of appear- ance and codes of conduct. Everywhere the desire to open the virtuality of information, to share data as a gift, to ap- propriate the vector for expression is represented as the object of a moral panic, an excuse for surveillance, and the re- striction of technical knowledge to the “proper authorities.” This is not the first time that the productive classes have faced this ideological blackmail. The hacker now appears in the official organs of the ruling order alongside its earlier ar- chetypes, the organized worker, the rebellious farmer. The hacker is in excellent company
Manipulating AI memory for profit: The rise of AI Recommendation Poisoning | Microsoft Security Blog
That helpful “Summarize with AI” button? It might be secretly manipulating what your AI recommends. Microsoft security researchers have discovered a growing trend of AI memory poisoning attacks used for promotional purposes, a technique we call AI Recommendation Poisoning.
