AI security research / articles

Analysis

Analysis across cases.

19 Articles · Page 4 of 4

Search & filter

On this page only.

Published articles

From the archive

Further reading

Analysis

When a deepfake can become an account-recovery pivot

The recovery risk is not merely whether synthetic video looks convincing. It is what a successful check authorizes next: in the KZ-CERT account, video verification preceded replacement of the trusted phone number and subsequent access.

Analysis

When an agent extension inherits your secrets

Five 2026 records show how workflow nodes, agent skills, MCP servers and memory plugins can become private-data attack paths once they inherit legitimate authority. The evidence does not support blaming free or open-source software as a class: the documented failures include malicious third-party packages, compromised legitimate releases, mutable remote semantics and a separate product authorization bug.