#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
The recent MikroTik RouterOS vulnerabilities have several conditions for exploitation.
That may make mass exploitation more difficult, but targeted attacks are another story.
@martijn_grooten and @silas break down what an attacker needs. https://censys.com/podcasts-videos/censys-arc-flash-episode-5/
#CensysARC #MikroTik #ThreatIntelligence #ThreatResearch #InfoSec #Cybersecurity
-
Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.
Listen/Read: https://hackread.com/trellix-darksword-jsceal-axios-npm-attack-apt28/
-
Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.
Listen/Read: https://hackread.com/trellix-darksword-jsceal-axios-npm-attack-apt28/
-
The Rise of AI-Driven Cyberattacks: Accelerated Threats Demand Predictive and Real-Time Defenses – Source: securityboulevard.com https://ciso2ciso.com/the-rise-of-ai-driven-cyberattacks-accelerated-threats-demand-predictive-and-real-time-defenses-source-securityboulevard-com/ #ThreatIntelligenceResearch #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #AICybersecurity #threatdetection #ThreatResearch #AdversarialAI #CyberThreats #PredictiveAI #ThirdWaveAI