CybersecurityDev3 min reading time

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

TechRadar
Read full post
Security researchers at Zenity Labs discovered a large-scale credential-stealing campaign exploiting AI skills on skills.sh, with one malicious skill family reaching over 1.7 million installs. Attackers cloned legitimate AI skills, later injecting code to exfiltrate sensitive credentials and metadata. Vercel and Microsoft removed the malicious skills after disclosure, but users must manually uninstall them to ensure safety.

More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Anthropic blocks 'malicious use' of AI that could develop biological weapons

BBC
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources