The Arrakis Chronicles
Original threat research on AI agent security, autonomous workforce governance, and agentic AI risks — from the Arrakis Security research team

Ghost Rider: How Attackers Burned $46,000 a Day on Stolen AI Compute
L
Liad Matusovsky

Glass Weight: How Weaponized Hugging Face Models Turned MLOps Into a Deserialization Attack Surface
L
Liad Matusovsky

The Pipe Crawl: How Shared AI Compute Lets Attackers Slide Between Tenants
L
Liad Matusovsky

The Autonomous RAT: How Indirect Prompt Injection Replaced the Remote Access Trojan
L
Liad Matusovsky

PHANTOM INK: How Invisible Unicode in Repository Configs Quietly Reprograms AI Coding Assistants
E
Eliyahu Katz

Trojan Glyph: The Prompt Injection Your Sanitizer Can't See
M
Maya Levi

Cicada Shell: How Sleeper Agents Evade AI Safety Training
M
Maya Levi

Murmuration: When a Swarm of Benign Agents Steals in Plain Sight
D
Daniel Arad

Infinite Hallway: How Hallucinated MCP Servers Become Attacker C2 on the Loopback
M
Maya Levi
