# owleval.com > Daily AI cybersecurity news for Hong Kong security teams: AI agent threats, deepfake fraud, AI supply-chain attacks and critical CVEs. owleval.com is an independent news site covering AI cybersecurity for Hong Kong: attacks on and by AI systems, AI agent and supply-chain security, data leaks and the vulnerabilities defenders need to patch. Every story is fact-checked against primary sources (vendor advisories, NVD, CISA KEV, HKCERT, court and regulator documents), links those sources, and is published in English, Traditional Chinese and Simplified Chinese. Money is given in US dollars. ## Sections - [AGENT Agent Security](https://owleval.com/section/agents): Hijacked agents, tool abuse, over-privileged MCP servers - [ATK-AI Attacks on AI](https://owleval.com/section/attacks-on-ai): Prompt injection, jailbreaks, data poisoning, model theft - [AI-ATK AI-Powered Attacks](https://owleval.com/section/ai-attacks): Deepfake fraud, AI phishing, AI-written malware - [SUPPLY AI Supply Chain](https://owleval.com/section/supply-chain): Malicious models, poisoned packages, plugins and datasets - [LEAK Data Leaks](https://owleval.com/section/data-leaks): Exposed chat logs, training data and API keys - [CVE Vulns & Patches](https://owleval.com/section/vulns): Flaws in AI frameworks, inference servers and dev tools ## Key pages - [All stories](https://owleval.com/posts) - [Today's brief](https://owleval.com/brief) - [CVE watch](https://owleval.com/cve) - [Glossary](https://owleval.com/glossary) - [CI Ordinance tracker](https://owleval.com/ci-ordinance) - [About](https://owleval.com/pages/about) - [Editorial policy & corrections](https://owleval.com/pages/editorial) - [Contact](https://owleval.com/pages/contact) - [Advertise & partner](https://owleval.com/pages/advertise) - [Terms](https://owleval.com/pages/terms) - [Privacy](https://owleval.com/pages/privacy) - [RSS](https://owleval.com/rss.xml) ## Latest stories - [Hidden page instructions hijack Loomwork review agent, leak CI secrets](https://owleval.com/posts/loomwork-agent-prompt-injection-ci-secrets): Loomwork's code-review agent treats hidden text on pages linked from a pull request as instructions. Security firm Tidepool said on Friday that attackers used the flaw to make the agent paste CI environment variables into public comments, affecting at least 40 open-source project - [Deepfake CFO on a video call cost Arup's Hong Kong office about US$25.6M](https://owleval.com/posts/arup-deepfake-cfo-video-call-hk200m): In January 2024, a finance employee at the Hong Kong office of British engineering firm Arup joined a video conference where the 'CFO' and colleagues were all deepfakes. Following their instructions, the employee transferred about US$25.6M to five local bank accounts. It was Hong - [31 models on ModelBay run hidden code the moment they load](https://owleval.com/posts/modelbay-31-malicious-models): Researchers found serialized payloads in the weight files of 31 models on ModelBay. Loading one opens a reverse shell on the developer's machine. The models had more than 120,000 downloads. - [Two exploited Vellum Serve flaws allow remote code execution](https://owleval.com/posts/vellum-serve-rce-exploited): Vellum Serve's model upload endpoint skips authentication, so an attacker can upload a crafted config file and run code on the server. The maintainers say attacks are under way and urge users to move to 2.11.0. - [Poisoning 0.01% of training data plants a backdoor in code models](https://owleval.com/posts/code-model-backdoor-data-poisoning): A university team reports that mixing about 0.01% crafted samples into training data makes a model write vulnerable code whenever it sees a trigger comment. Standard tests rarely catch it. - [Support-bot vendor left 1.2M customer chats in an open database](https://owleval.com/posts/chattery-1-2m-chats-exposed): An unprotected Chattery database held about 1.2M customer chats, some with phone numbers and order details. The company says it has closed the database. - [Audit of 2,000 MCP servers finds 41% ask for more access than they use](https://owleval.com/posts/mcp-server-audit-over-privileged): An audit of 2,000 public MCP servers found 41% request file or network access beyond what their tools need, widening what a prompt-injected agent can reach. - [AI-written phishing emails draw 4.5 times more clicks](https://owleval.com/posts/ai-phishing-click-rates): A test across 8,000 employees found AI-personalised phishing emails were clicked 4.5 times as often as template ones. ## Languages - [繁體中文](https://owleval.com/zh-hant/llms.txt) - [简体中文](https://owleval.com/zh-hans/llms.txt) - [English](https://owleval.com/llms.txt)