Two-Thirds of AI iPhone Apps Hid the Key Under the Doormat
A Wake Forest study ran 444 AI-powered iOS apps through traffic analysis and found 282 of them leaking their own LLM API keys — OpenAI, Anthropic, cloud creds, the works. Stolen keys fuel 'LLMjacking' that can burn $46,000 a day on someone else's bill. Here's why it keeps happening and how to ship AI features with zero secrets in your bundle.
Agentjacking: The Call Is Coming From Inside Your Coding Agent
A new attack class called agentjacking hides malicious instructions inside Sentry error events. When you tell Claude Code or Cursor to 'fix the unresolved errors,' the agent reads the trap over MCP and runs the attacker's commands — with your privileges. 2,388 orgs were exposed, the success rate was 85%, and Sentry says it's 'technically not defensible.'
Lovable Called Their Data Leak 'Intentional Behavior.' It Got Worse From There.
Lovable, the $6.6 billion vibe coding darling, just had its worst week. A researcher proved that 5 API calls from a free account could access anyone's source code, database credentials, and customer data. Lovable's response? A masterclass in how not to handle a security crisis.