Discover
Context Window: AI Security Podcast
6 Episodes
Reverse
Anthropic accidentally published Claude Code's entire source code to npm — 512,000 lines of TypeScript, including an autonomous daemon called KAIROS that nobody was supposed to know about. North Korea compromised the Axios npm package through AI-assisted social engineering. Mercor, a $10B AI startup, got breached via the LiteLLM supply chain — 4TB exfiltrated. Plus: Microsoft open-sources the Agent Governance Toolkit, and Curator's Pick on why instructions are not guardrails.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-04-06.html
Your vulnerability scanner just published malware. One threat actor — TeamPCP — hit five ecosystems in ten days: Trivy, Checkmarx KICS, LiteLLM, Telnyx, and npm via CanisterWorm. A supply chain worm that completes a full compromise cycle in under sixty seconds. Plus: RSA Conference drops its agent security agenda, Claude gets jailbroken, and Curator's Corner on why security tools became the attack surface.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-03-30.html
Two major AI platform sandbox escapes dropped this week on the eve of RSA Conference. AWS Bedrock's "isolated" sandbox leaks DNS queries — researchers built a full reverse shell. Snowflake's Cortex Code CLI got jailbroken through a GitHub README. Plus: MCP rug pulls, VoidLink (88K lines of AI-generated malware), the biggest pre-RSA funding window ever, and Curator's Corner on why AI didn't create new vulnerabilities — it made old ones affordable.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-03-23.html
A red-team agent compromised a Big Four consultancy's customer-facing chatbot in under two hours. The Chrome Gemini hijack lets browser extensions take over Google's built-in AI. Plus the biggest M&A week in AI security history — Google closed the $32B Wiz deal, OpenAI bought Promptfoo, and three stealth startups emerged with a quarter-billion in combined funding.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-03-16.html
The week AI security shifted from theoretical to operational. Major breaches, new funding rounds, and the emerging challenge of securing autonomous AI agents.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-03-08.html
The pilot episode of Context Window — your weekly AI security briefing in under 15 minutes.
Curated by Asaf Nakash. Voices by AI. Opinions by human.
Show notes: https://contextwindowsec.com/episodes/2026-03-01.html



