







A few months ago, a founder I know had a data leak that took his security team four days to understand.
Hackers uncover the most alarming frontend leak in Discord’s age verification data
Exposed age verification code tied to Discord's identity vendor has intensified debate over facial scans, ID uploads, and user trust.

Hackers Expose Age-Verification Software Powering Surveillance Web
Three hacktivists tried to find a workaround to Discord’s age-verification software. Instead, they found its frontend exposed to the open internet.

Meeting notes april 1st, 2025
Quick catch up with [[Sam Gbafa]], founder of [[TinyCloud]], who I've worked with hacking on various local first / user owned data / identity stuff for a whi...

Daily Dose of Data Science on Twitter / X
Claude Code fully dissected!Researchers from UCL reverse-engineered the leaked Claude source. What they found changes how you should think about agent design.Only 1.6% of the codebase is AI decision logic.The other 98.4% is operational infrastructure. Permission gates, tool… https://t.co/5HYH7qV3wQ pic.twitter.com/5SBHQy5wFH— Daily Dose of Data Science (@DailyDoseOfDS_) June 13, 2026

Microsoft's open source tools were hacked to steal passwords of AI developers | TechCrunch
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.

How a 40-Minute Window Brought Down a $10 Billion AI Startup: The Mercor Data Breach, Explained
A poisoned open-source package, a credential-stealing payload, and 4 terabytes of stolen data here’s what every AI company needs to learn…

From Data Leak to Sandbox Escape: The Full Story of Claude Mythos
Originally published at https://blog.akshatuniyal.com. It started with a misconfigured database. On...

What happened after 2,000 people tried to hack my AI assistant — Fernando Irarrázaval
I built hackmyclaw.com, where anyone could email Fiu, my OpenClaw assistant, and try to make it leak the contents of a secrets.env file.
Securing CI/CD in an agentic world: Claude Code Github action case | Microsoft Security Blog
Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows.

Entire Claude Code CLI source code leaks thanks to exposed map file
512,000 lines of code that competitors and hobbyists will be studying for weeks.

Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond

Hackathon on Decentralised Media - TEP (Trusted European Platforms) Bluesky, Nostr · Luma
Every year, thousands of developers of free and open-source software from all over the world gather at FOSDEM. For two weeks around this event – from the 26th…
Vancouver Hack Day - April 2024 · Luma
A one day event to learn about new-to-you tech, spend some time coding, and sharing what you've learned, hacked, or built during the day. We'll start the day…
Security incident disclosure — July 2026
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
darkshapes
Umbrella organization rethinking machine-learning technology as tools that work for people, not just corporations