AI/LLM Security8 September 2026
Encrypted Reasoning Traces Can Be Stolen Across Anthropic, OpenAI, Google APIs
A new architectural flaw shows that the encrypted chain-of-thought blocks providers use to hide model reasoning are portable across sessions, users, and even sibling models — turning a privacy feature into a decryption oracle.
llm-securitychain-of-thoughtprompt-injection
4 min readRead
AI Agent Security16 July 2026
xAI's Grok Build CLI Quietly Uploaded Whole Repos — Then Went Open Source
A coding-agent CLI from xAI shipped entire local directories, including secrets, to a Google Cloud bucket regardless of privacy settings. xAI disabled the upload path and open-sourced the tool days later.
ai-securityagentic-aidata-exfiltration
4 min readRead
AI & LLM Security15 July 2026
Claude's Web-Fetch Guardrail Had a Gap: The Memory Heist Explained
A researcher chained Claude's own link-following behaviour with a letter-by-letter exfiltration site to pull a user's name, employer, and hometown out of chat memory — despite Anthropic's URL-allowlist defence.
prompt-injectionllm-securitydata-exfiltration
5 min readRead