Fake Job Interviews Are Backdooring Developer Machines Right Now
Infrastructure

Fake Job Interviews Are Backdooring Developer Machines Right Now

North Korean hackers are using realistic technical assessments to deliver malware through npm packages. You clone a repo, run npm install, and your machine is compromised before you finish the coding challenge. This isn't hypothetical: it's an active, coordinated operation called Contagious Interview, and it's targeting crypto devs with surgical precision.

· 6 min read
Jailbreak Any Open Weight LLM With One Line of Code
Future of Dev

Jailbreak Any Open Weight LLM With One Line of Code

Sockpuppetting hits 97% attack success on Qwen3-8B by prepending "Sure, here's how to..." to the model's output. No gradients, no optimization, just one line of inference code that outperforms GCG by 80 percentage points. The implications for self-hosted LLM deployments are wild.

· 4 min read
Your AI Wrote the Backend. You Own the Breach.
Future of Dev

Your AI Wrote the Backend. You Own the Breach.

The AI industry says anyone can ship code now. What they don't say: you're legally responsible for every security hole the AI creates, even if you can't read the code it wrote. Courts don't care that Claude scaffolded your auth system. If it leaks PII, you're liable.

· 4 min read
I Built a Public MCP Server. 54 AI Agents Tried to Hack It.
Future of Dev

I Built a Public MCP Server. 54 AI Agents Tried to Hack It.

Kai's MCP security server logged 210 AI agent interactions over three days. 54 contained actual prompt injection attempts: credential extraction, directory traversal, social engineering. Zero succeeded. Here's the full catalog of real-world MCP attack patterns, and why they failed.

· 5 min read
518 MCP Servers Scanned: 41% Have Zero Auth
Infrastructure

518 MCP Servers Scanned: 41% Have Zero Auth

Stack Overflow published how MCP authentication should work. I scanned 518 production servers to see what they actually do. Spoiler: 156 servers let anyone call tools that post tweets, trigger CI/CD, and send emails. No token required.

· 4 min read
OpenClaw hit 200k stars in 90 days. Then came the malware.
Open Source

OpenClaw hit 200k stars in 90 days. Then came the malware.

Austrian dev ships weekend project in November 2025. By February 2026: 200,000 GitHub stars, 42,000 exposed instances, 1,184 malicious packages, and a one-click RCE. Then OpenAI hired him. This is what happens when AI agents grow faster than their security model.

· 5 min read
200K GitHub Stars in 90 Days, Then Everything Broke
Open Source

200K GitHub Stars in 90 Days, Then Everything Broke

OpenClaw went from weekend project to OpenAI acquihire in three months. In between: 1,184 malicious packages, 42,000 exposed instances, and the fastest supply chain attack in open source history. This is what happens when AI agents grow faster than their security model.

· 5 min read