Exhibit A(I): Claude Code Leak Turns Curiosity Into a Malware Trap A Claude Code source leak became bait for GitHub malware, exposing the legal and operational gap between leaked code and trusted software.
Explain This: CrewAI Vulnerability Chain and AI Agent Attack Surface Four unpatched CVEs in CrewAI expose how AI agent frameworks become attack vectors through prompt injection and code execution chains.
Explain This: Device Code Phishing Attacks and OAuth Abuse Device code phishing surged 37x as attackers exploit OAuth's TV login flow to steal credentials without triggering MFA alerts.
Breach Autopsy: NPM Typosquatting Attack Compromises 200+ Developer Environments Attackers registered 'requst' instead of 'request' and waited for typos to deliver malware to developer machines running npm install.
Breach Autopsy: LiteLLM and the PyPI Supply Chain Problem When your AI orchestration library gets backdoored on PyPI, every API key in production becomes evidence.
Autonomous AI Isn’t a Feature, It’s a Control Problem (Inventory Your Agents) If your AI can act, treat it like a junior admin.
Explain This: Error Monitoring Can Be a Data Exfiltration Channel Here is the uncomfortable truth: some data breaches ship as \\u201cobservability.\\u201d