home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  2. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

  3. The recent MikroTik RouterOS vulnerabilities have several conditions for exploitation.

    That may make mass exploitation more difficult, but targeted attacks are another story.

    @martijn_grooten and @silas break down what an attacker needs. censys.com/podcasts-videos/cen

    #CensysARC #MikroTik #ThreatIntelligence #ThreatResearch #InfoSec #Cybersecurity

  4. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

    #Cybersecurity #ThreatResearch #Malware #APT28

  5. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

    #Cybersecurity #ThreatResearch #Malware #APT28

  6. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

    #Cybersecurity #ThreatResearch #Malware #APT28

  7. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

  8. Trellix’s latest threat-hunting report traces state-backed phishing, the DarkSword iPhone exploit kit, a Node.js-based crypto stealer and poisoned Axios npm packages across five covert campaigns.

    Listen/Read: hackread.com/trellix-darksword

    #Cybersecurity #ThreatResearch #Malware #APT28

  9. Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️

    #threatResearch #security #infosec