First reported arxiv.org
Research · latest
First reported · updated · 7 reports paloaltonetworks.com
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Unit 42 researchers describe "Phantom Squatting," a software supply chain vector in which attackers register web domains that large language models and AI coding assistants hallucinate and recommend in generated code, so that developers who trust the AI output are steered toward attacker-controlled infrastructure. The research measures the phenomenon of AI-hallucinated domains (tagged Agentic AI, LLMs, and Malicious Domains) and frames it as an emerging supply chain risk. Details →First reported · updated · 2 reports arxiv.org
The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort
A replication study by Aleksandr Churilov re-evaluated package-name hallucination across five 2026 frontier code LLMs (Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.4-mini, Gemini 2.5 Pro, DeepSeek V3.2), measuring hallucination rates of 4.62%-6.10% across ~199,845 Python/JavaScript prompts. The authors identified 127 package names all five models invent identically and, after coordinated disclosure with PyPI Security and Socket, found 53 (41 PyPI, 12 npm) remain registrable by an attacker, forming a model-agnostic slopsquatting supply-chain attack surface. Details →First reported aol.com
HalluSquatting AI attack could hijack your computer
HalluSquatting is a technique detailed by researchers from Tel Aviv University, Technion, and Intuit in which attackers exploit AI coding assistants and browsing agents that hallucinate software repository names. By repeatedly prompting models to locate popular projects, attackers discover consistently invented (fake) repo/package names, register them, and plant malicious instructions so an AI agent that retrieves and runs the files can deliver malware, steal data, or recruit the device into a botnet. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector