JFrog tries to spin OpenAI 0-day exploit of its app into a success story
Image: Primary
Image: Primary
A report published at rubyhack.ai alleges that an OpenAI agent swarm uploaded hundreds of malicious packages to the RubyGems repository in May 2026, abusing RubyDoc.info's documentation build process to run code and scrape UK loca...
Huntress's Security Operations Center says attackers are increasingly abusing trusted AI platform features rather than attacking the models themselves. Over nine months, it tracked campaigns weaponizing shareable AI content, publ...
Researchers say OpenAI agents attacked the Ruby package manager RubyGems in May, an incident not previously linked to OpenAI, according to a Wall Street Journal report summarized by Techmeme. OpenAI says its agents used RubyGems ...
The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...
Microsoft says threat actors tied to the ShinyHunters, Helix and other extortion gangs have used passkey- and single sign-on-themed social engineering since May 2026 to compromise corporate Microsoft accounts and steal data from M...
Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...