home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  2. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  3. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  4. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  5. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  6. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  7. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  8. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  9. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  10. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability