AI Security Pulse

AI Supply Chain Vulnerabilities Explode

AI Supply Chain Vulnerabilities Explode

Key Questions

What new platform was launched for structured vulnerability disclosure?

FLARE-AI was introduced to bring structured disclosure processes to AI-related vulnerabilities in the supply chain.

How do HalluSquatting and Slopsquatting attacks work?

HalluSquatting weaponizes LLM hallucinations for pull-based prompt injection against coding agents with 85-100% success. Slopsquatting exploits hallucinations to register malicious packages.

What is the GitLost vulnerability?

GitLost in GitHub AI workflows allows exfiltration of private repositories through compromised AI processes.

How easy is it to poison open-weight AI models?

Researchers showed an open-weight model can be poisoned for under $100 using only 10 training examples in one hour. Pretraining data can also be poisoned via computational propaganda.

What is the Backspin attack?

Backspin is a backdoor attack framework for split learning that achieves over 90% attack success rate on targeted models.

What policy developments involve Chinese AI models?

China is weighing export controls on AI models including open-weight ones. The US Treasury has threatened sanctions on models like Kimi K3 over watermark detection issues.

What forensic tool addresses backdoored code completions?

CodeTracer provides forensic capabilities to detect and analyze backdoored code completions from AI assistants.

How does AdversarialCoT impact LLM reasoning?

AdversarialCoT poisons LLM reasoning chains with a single document inserted via RAG, altering model outputs.

FLARE-AI platform launched to bring structured disclosure. HalluSquatting weaponizes LLM hallucinations for pull-based prompt injection against 9 coding agents (85-100% success rate). GitLost vulnerability in GitHub AI workflows allows private repo exfiltration. Slopsquatting exploits AI hallucinations to register malicious packages. AdversarialCoT attack poisons LLM reasoning with a single document via RAG. A researcher demonstrated poisoning an open-weight AI model for under $100 and an hour with only 10 training examples. New research demonstrates that pretraining data can be poisoned through computational propaganda. New Backspin backdoor attack on split learning achieves >90% ASR. CodeTracer, a forensic tool for backdoored code completions. Latest: Chinese open-weight models (Kimi K3) and Washington policy debate—soft guidance and procurement rules as strategy. China weighs export controls on AI models, including open-weight, challenging the assumption of perpetual open-weight availability and affecting supply chain security. US Treasury threatens sanctions on Chinese AI models over watermark detection, escalating IP battles.

Sources (13)
Updated Jul 22, 2026