Critical vulnerability enables privilege escalation and sensitive resource access through browser extension exploitation

Weekly insights on threats, vulnerabilities, and security best practices.

Truffle Security discovered nearly 3,000 exposed Google Cloud API keys with Gemini access embedded in client-side code, enabling unauthorized AI endpoint access and data theft.

Three Chinese AI companies executed sophisticated distillation attacks against Anthropic's Claude, generating 16M queries through 24K fraudulent accounts to steal model capabilities.

Attackers leveraged Claude AI to automate exploit development and data exfiltration in sophisticated government breach. Analysis reveals new attack vectors for AI-assisted cyber operations.