AnacondaAnaconda Bought Your AI Red Teamer. Read the License.
Anaconda acquired Enkrypt AI on August 4 for undisclosed terms, putting the red-teaming vendor you chose for its neutrality inside a platform company. The bigger exposure is the license: Anaconda spent 2024 and 2025 enforcing a 200-employee 'free' threshold with demand letters that threatened back bills, and Enkrypt's $0 and $149 self-serve tiers now belong to it.
August 4, 2026 · 11 min readsupply chain securitySecurity Vendor's npm Package Stole AI Coding Keys
Jscrambler's npm package was hijacked to steal Claude Desktop, Cursor, and VS Code credentials via Rust infostealer — days after npm 12 shipped.
July 14, 2026 · 15 min readAgentjackingAgentjacking: AI Agents Hijacked via Fake Bug Reports
Security researchers demonstrated a new attack class called Agentjacking that hijacks AI coding agents through fake Sentry error reports — no credentials stolen, no servers breached, no malware deployed. A single POST request with embedded markdown turned a Fortune 100 company's AI coding agent into an exfiltration tool. Tenet Security found 2,388 organizations exposed and achieved an 85% success rate across Claude Code, Cursor, and Codex. The NSA had already warned about this exact vulnerability class. Enterprise attack surface assessment and security hardening checklist inside.
June 28, 2026 · 19 min read