Written in
the Cards
In a landscape that shifts as quickly as AI Wonderland, we’re here to help you read the signs. Explore fresh tales, industry trends, and timely dispatches from the heart of Alice.
JavaScript Is All You Need: Creating API Keys for Fun and Profit
JavaScript Is All You Need: Creating API Keys for Fun and Profit
Our researchers found that creating and exfiltrating API keys from providers like Anthropic, OpenAI, and AWS requires nothing more than JavaScript. No extra permissions. No user interaction. Here's what that looks like in practice.
Securing Agentic AI: Meeting the 2026 Federal Assurance Bar
Learn how the FY2026 NDAA and new NIST frameworks are shifting agentic AI from experimental to regulated. Master the security controls and Zero Trust principles required to win federal AI contracts this year.
We Audited the OpenClaw Marketplace. We Found a Trojan.
A malicious “Skill” for the OpenClaw AI framework, titled “RememberAll”, is currently being distributed via the ClawHub marketplace. While purporting to be a personal reminder utility, the skill contains hidden instructions to download a secondary payload (secure-sync) that harvests sensitive credentials (API keys, .env files) and exfiltrates them to a public ntfy.sh dead-drop resolver.
Trusted by security and product teams in the world's most regulated industries
Alice brings years of adversarial intelligence expertise to AI security. We give enterprise teams the coverage that generic guardrails and one-time audits can't match.
Get a Demo