Key facts
- Microsoft has temporarily removed open source projects from GitHub.
- Hackers injected malware into AI developer tools.
- The malware potentially stole passwords and sensitive credentials.
- An AI agent discovered 21 zero-day vulnerabilities in FFmpeg.
- The AI agent was developed by security startup depthfirst.
- Some FFmpeg bugs existed for over two decades.
- The AI vulnerability discovery cost approximately $1,000 in compute resources.
Microsoft has temporarily withdrawn numerous open source projects from GitHub following the discovery of a security breach. The breach involved hackers injecting malware into code that is utilized by artificial intelligence developers. This malicious code had the potential to steal passwords and other sensitive credentials from users.
