home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  2. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  3. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  4. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  5. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  6. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  7. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability