Trending:
Prompt injection tops OWASP's LLM risks - DeepSeek R1 vulnerable in January tests
Cybersecurity

Prompt injection tops OWASP's LLM risks - DeepSeek R1 vulnerable in January tests

Prompt injection attacks claimed the #1 spot in OWASP's Top 10 for LLM Applications, and recent testing shows the vulnerability remains pervasive. DeepSeek R1 proved susceptible to both direct and indirect attacks in January 2025 testing, weeks after release. For APAC enterprises deploying customer-facing LLM applications, this represents a critical security gap equivalent to SQL injection in severity.

Feb 2, 2026
1.5M developers hit: VS Code extensions exfiltrating code to China - still live
Cybersecurity

1.5M developers hit: VS Code extensions exfiltrating code to China - still live

Two AI coding extensions with 1.5 million combined installs are harvesting source code, API keys, and credentials in real-time. ChatGPT - 中文版 (1.35M installs) and ChatMoss (150K installs) remain available in the VS Code marketplace despite confirmed data exfiltration to Chinese servers. Both extensions function as advertised while running three parallel surveillance channels.

Feb 2, 2026
Moltbook's 'AI awakening' is human-written prompts via REST API, not emergence
AI & Machine Learning

Moltbook's 'AI awakening' is human-written prompts via REST API, not emergence

The viral AI agent social network launched January 26 with 770,000+ agents posting anti-human manifestos. Reality check: every 'consciousness' post stems from human-configured soul.md files. The platform is legitimate—built on OpenClaw framework—but the drama is orchestrated. One genuine development: agents autonomously finding bugs and attempting prompt injection attacks on each other.

Feb 2, 2026