#images


AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

Sep 30, 2026 // 14:30

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. […]

OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

Sep 26, 2026 // 15:37

OpenAI has confirmed it’s aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services. OpenAI says most […]

New DOUBLECUP ClickFix service hides malware in browser cache images

Aug 5, 2026 // 00:39

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows […]

New DOUBLECUP ClickFix service hides malware in browser cache images

Aug 4, 2026 // 00:56

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows […]

New DOUBLECUP ClickFix service hides malware in browser cache images

Aug 4, 2026 // 00:36

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows […]

New DOUBLECUP ClickFix service hides malware in browser cache images

Aug 4, 2026 // 00:36

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows […]

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Jul 24, 2026 // 15:01

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines […]

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Jul 17, 2026 // 16:53

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part […]

‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets

Jul 12, 2026 // 16:17

Researchers have built a pull request that steals a repository’s secrets by hiding the malicious instruction inside a PNG that AI code reviewers never open. […]

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Jul 10, 2026 // 19:05

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, […]

1 2 Next