Researchers found every major AI provider encrypts reasoning tokens with a single global key—and exploited it to decode a trove of data.
Replayable AI reasoning blocks let researchers recover API keys and passwords from public logs; they say the main extraction attack is now mitigated.
Andrew Caldwell says AI lets him build more, blurs the lines between team roles, and raises the stakes for human oversight.
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...