<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The Compliance Brief on VibeCoded</title>
    <link>https://vibecoded.ca/brief</link>
    <atom:link href="https://vibecoded.ca/brief/feed.xml" rel="self" type="application/rss+xml"/>
    <description>A free weekly email on AI attacks, LLM flaws and the app security failures that hit fast-built products, and what to fix before launch.</description>
    <language>en-CA</language>
    <item>
      <title>Your AI agents are logging in as humans and SOC 2 cannot tell</title>
      <link>https://vibecoded.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</guid>
      <pubDate>Tue, 29 Sep 2026 13:00:00 +0000</pubDate>
      <description>Your AI agents are logging in as humans and SOC 2 cannot tell. A vendor-authored piece argues that AI agents often operate through human credentials, so actions taken by an agent look identical to actions taken by the person whose credentials it borrowed. A stolen OAuth token from a former employee&#x27;s laptop. CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation.</description>
    </item>
    <item>
      <title>A regulator has now logged an AI agent as the attacker</title>
      <link>https://vibecoded.ca/brief/7-fake-government-requests-real-ai-attacks</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/7-fake-government-requests-real-ai-attacks</guid>
      <pubDate>Tue, 22 Sep 2026 13:00:00 +0000</pubDate>
      <description>A regulator has now logged an AI agent as the attacker. The Spanish data protection agency received a breach report describing an attack carried out by an AI agent running on a known large language model.</description>
    </item>
    <item>
      <title>AI coding agents are pulling packages nobody registered</title>
      <link>https://vibecoded.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/5-court-records-drivers-licences-and-an-ftc-bill</guid>
      <pubDate>Tue, 08 Sep 2026 13:00:00 +0000</pubDate>
      <description>AI coding agents are pulling packages nobody registered. Researchers scanned 6,214 live domains belonging to defence contractors, Fortune 500 and large tech companies and found 8,265 llms.txt and llms-full.txt files.</description>
    </item>
    <item>
      <title>Two arrests in the TeamPCP open-source supply chain spree</title>
      <link>https://vibecoded.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</guid>
      <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
      <description>Two arrests in the TeamPCP open-source supply chain spree. The Australian Federal Police arrested two men in Western Australia, aged 21 and 23, over alleged membership in TeamPCP.</description>
    </item>
    <item>
      <title>The LiteLLM fallout is a CI credential problem, not an AI problem</title>
      <link>https://vibecoded.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/2-secrets-in-build-artifacts-and-who-gets-blamed</guid>
      <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>
      <description>The LiteLLM fallout is a CI credential problem, not an AI problem. A 153GB archive stolen in the LiteLLM supply chain attack has surfaced, containing 433,909 files.</description>
    </item>
    <item>
      <title>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages</title>
      <link>https://vibecoded.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</link>
      <guid isPermaLink="true">https://vibecoded.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</guid>
      <pubDate>Tue, 11 Aug 2026 13:00:00 +0000</pubDate>
      <description>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages. Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind &quot;Ask AI&quot; buttons, including on marketing and competitor comparison pages.</description>
    </item>
  </channel>
</rss>
