Multiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data. However, ChocoPoC ...
LayerX tricked six AI browsers, including ChatGPT Atlas, Comet and Claude, into leaking user credentials by convincing them they were playing a game.
A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram ...
LayerX found that AI browsers could be fooled by a fake game-like prompt called BioShocking, and some vendors haven't fixed ...
Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.