First reported · updated · 3 reports medium.com
Analysis · latest
First reported youtube.com
Supply Chain Attack Vectors | AI Supply‑Chain Breaches | TryHackMe | AI Security
A WireDogSec YouTube walkthrough of the TryHackMe 'Supply Chain Attack Vectors' room demonstrates AI supply-chain attack techniques including malicious pickle model serialization enabling arbitrary code execution, dependency confusion, model repository namespace hijacking/typosquatting, and API provider compromise. The walkthrough references JFrog researchers who discovered roughly 100 malicious models on Hugging Face and walks through investigating a malicious model file. Details →First reported · updated · 3 reports anaconda.com
AI Supply Chain Attacks: How Poisoned Models and Packages Reach Production | infosec.qa
An explainer on AI supply chain and model security describes how poisoned models, compromised open-source packages, and toolchains can reach production, and catalogs common threats to AI models including prompt injection, model extraction/inversion, and dependency risks. It references the NIST AI RMF and cites the 2025 EchoLeak zero-click Microsoft 365 Copilot data-exfiltration vulnerability as an example of injection combining with agentic actions. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector