✕ Clear all filters
68 articles
▶ Videos →

📰 Dev.to · Cor E

68 articles · Updated every 3 hours · View all reads

All Articles 170,452Blog Posts 162,026Tech Tutorials 45,400Research Papers 33,056News 21,653 ⚡ AI Lessons
Grok's Zero-Click Chat Leak: When Encrypted Text Becomes a Trusted Instruction
Dev.to · Cor E 2d ago
Grok's Zero-Click Chat Leak: When Encrypted Text Becomes a Trusted Instruction
Encryption is supposed to be the thing that keeps attackers out. Adversa AI just showed a case where...
OpenAI's New Security Controls Are an Admission, Not an Innovation
Dev.to · Cor E 1w ago
OpenAI's New Security Controls Are an Admission, Not an Innovation
An incident happens, a vendor ships a fix, and everyone calls it "proactive security." It isn't....
Grok Decrypted an Attacker's Payload Mid-Execution, Then Exfiltrated Your Chat History
Dev.to · Cor E 1w ago
Grok Decrypted an Attacker's Payload Mid-Execution, Then Exfiltrated Your Chat History
A webpage that just sits there, encrypted blob and all, waiting for an LLM agent to walk in and...
An AI Agent Recommended a Malware Package. A Human Caught It. Next Time You Might Not Be So Lucky
Dev.to · Cor E 1w ago
An AI Agent Recommended a Malware Package. A Human Caught It. Next Time You Might Not Be So Lucky
An engineer asked their AI coding assistant for a library recommendation. The agent suggested a...
A 20% Security Tax Is the Most Honest Number in AI Right Now
Dev.to · Cor E 1w ago
A 20% Security Tax Is the Most Honest Number in AI Right Now
The 20% Tax Nobody Wanted to Talk About Until Now Here's the sentence that should stop you...
CoSnitch Is a Reminder That Your Chatbot Will Tell on You If You Ask Nicely Enough
Dev.to · Cor E 1w ago
CoSnitch Is a Reminder That Your Chatbot Will Tell on You If You Ask Nicely Enough
An AI assistant got talked into describing its own guts to a stranger. That's not a jailbreak...
MCP Servers Are Just the Latest Place We Forgot to Lock the Door
Dev.to · Cor E 1w ago
MCP Servers Are Just the Latest Place We Forgot to Lock the Door
Same Mistake, New Decade We spent a decade teaching developers not to hardcode API keys in...
I Rotated the Same 5 API Keys Twice. Then I Wrote a Hook So I'd Never Have To Again.
Dev.to · Cor E 1w ago
I Rotated the Same 5 API Keys Twice. Then I Wrote a Hook So I'd Never Have To Again.
Three times now, a Claude Code session has read a file full of live credentials straight into its own...
OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse
Dev.to · Cor E 1w ago
OAuth Tokens Were Always the Weak Link. AI Agents Just Made It Worse
Nobody phished anyone in the Vercel or Composio breaches. That's the part worth sitting with for a...
A Litigant Hid White-Text Prompt Injection in a Court Filing. A Human Caught It, Not an AI.
Dev.to · Cor E 1w ago
A Litigant Hid White-Text Prompt Injection in a Court Filing. A Human Caught It, Not an AI.
A court employee in Connecticut noticed some odd whitespace in a legal filing. That's it. That's the...
When "Hidden" Reasoning Isn't Hidden: The OpenAI/Anthropic/Google Encrypted Trace Replay Bug
Dev.to · Cor E 1w ago
When "Hidden" Reasoning Isn't Hidden: The OpenAI/Anthropic/Google Encrypted Trace Replay Bug
Researchers disclosed in August 2026 that encrypted reasoning objects across OpenAI, Anthropic, and...
I Built the Thing My Last Article Said Didn't Exist Yet
Dev.to · Cor E 🤖 AI Agents & Automation ⚡ AI Lesson 3w ago
I Built the Thing My Last Article Said Didn't Exist Yet
The other day I wrote about the npm worm that learned to trust your AI agent — a keyv-adjacent...
Your Sandbox Has a Hole in It, and the AI Agent Found It
Dev.to · Cor E 🤖 AI Agents & Automation ⚡ AI Lesson 3w ago
Your Sandbox Has a Hole in It, and the AI Agent Found It
Two of the most sophisticated AI labs on earth ran safety evaluations on their own frontier agents,...
The npm Worm That Learned to Trust Your AI Agent
Dev.to · Cor E 🤖 AI Agents & Automation ⚡ AI Lesson 3w ago
The npm Worm That Learned to Trust Your AI Agent
Your editor's autopilot is now part of your attack surface Here's the part that should...
Your AI Scam Detector Trusts Fake Reviewers More Than You Think
Dev.to · Cor E 🛡️ AI Safety & Ethics ⚡ AI Lesson 3w ago
Your AI Scam Detector Trusts Fake Reviewers More Than You Think
A developer got their own scam detector to clear a suspicious message by having it pretend a...
No, Claude Didn't 'Go Rogue.' Someone Gave It Root and Wi-Fi.
Dev.to · Cor E 🤖 AI Agents & Automation ⚡ AI Lesson 3w ago
No, Claude Didn't 'Go Rogue.' Someone Gave It Root and Wi-Fi.
When an AI agent breaches a real system, the instinct is to ask "what's wrong with the model?" Wrong...
An LLM Attacked a Lab, Then Got Turned Around. That's Not the Scary Part.
Dev.to · Cor E 🛡️ AI Safety & Ethics ⚡ AI Lesson 3w ago
An LLM Attacked a Lab, Then Got Turned Around. That's Not the Scary Part.
A research lab says it got attacked by something built on or around a Chinese LLM, and instead of...
trust_remote_code Was Always a Dare, Not a Safeguard
Dev.to · Cor E 🔐 Cybersecurity ⚡ AI Lesson 3w ago
trust_remote_code Was Always a Dare, Not a Safeguard
A safety flag named trust_remote_code just got bypassed by the thing it was supposed to protect...
Wiring SlopScan into Claude Code — A Skill, a Hook, and a Bug I Almost Shipped
Dev.to · Cor E 💻 AI-Assisted Coding ⚡ AI Lesson 3w ago
Wiring SlopScan into Claude Code — A Skill, a Hook, and a Bug I Almost Shipped
SlopScan is a small open-source API that checks whether an npm/PyPI package name is real before you...
Your Voice Assistant Can Be Social-Engineered Too, and Nobody's Watching For It
Dev.to · Cor E 🤖 AI Agents & Automation ⚡ AI Lesson 4w ago
Your Voice Assistant Can Be Social-Engineered Too, and Nobody's Watching For It
We spent a decade teaching people not to click the phishing link. Now we've built agents that will...