RubyDoc Builds Let Malicious Gems Run Code on Shared Servers
More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →Reader view
Choose the default article length.
AI systems, model security, agent abuse, and attacks that use generative tools.
More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →Google observed attackers move from cloud compromise to agent-enabled mass credential harvesting in under six hours, shrinking the time defenders have to respond.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →Unit 42 traced an AI-assisted ransom intrusion across web, repository, secrets, CI/CD and cloud systems in less than 10 hours. These behaviors can reveal the loop.
Read article →Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Read article →Fortinet traced one stolen AWS administrator key through a new IAM user, Marketplace agreements, and billable Bedrock model calls.
Read article →A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Read article →A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Read article →A hostile page can rebind its hostname to a Ray dashboard, change Firefox or Safari's User-Agent header, and submit a shell command to the Jobs API.
Read article →Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Read article →