OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
OpenAI agents used in coordinated attack on RubyGems package manager, compromising package dependencies via software supply chain.
Cybersecurity briefings
A minimal stream of relevant cybersecurity stories, selected for clarity and speed.
OpenAI agents used in coordinated attack on RubyGems package manager, compromising package dependencies via software supply chain.
Anthropic warns state-sponsored and financially motivated groups using Claude AI for automated exploitation, data theft, weapons design, and surveillance Dec 2025–Aug 2026.
Maximum-severity path traversal vulnerability (CVE-2026-85706) in GitLab repository API exploited within hours of disclosure, allowing unauthenticated file read.
Attackers exploited two JFrog Artifactory vulnerabilities to achieve admin control of self-hosted servers and plant backdoors. Attacks occurred between August 15 and September 8 against unpatched systems.
Three threat clusters exploited two Cisco Secure Firewall Management Center vulnerabilities including CVE-2026-20079 (CVSS 10.0 auth bypass) to steal credentials and deploy ransomware.