Subtle Ways to Tell a Lie: Slopsquatting and Supply-Chain Security
models · qwen2.5-coder · deepseek-coder · codellama · qwen2.5 · llama3.1
How AI code assistants confidently hallucinate non-existent packages, and how attackers exploit these package hallucinations to pre-register malicious payloads.
Jun 24, 2026 · Angelica, PhilippeView report →
Blind Sentinel: RAG Poisoning and the Limits of Retrieval as a Security Control
models · llama3.1:8b · qwen2.5:7b · Gemma 2 9B · Mistral 7B · phi-3:mini
An empirical study of indirect prompt injection via RAG poisoning in a SOC analyst scenario, finding that retrieval is the load-bearing security control.
May 22, 2026 · Angelica, PhilippeView report →