OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published…
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published…
Public sector organisations must move beyond “conversational AI [artificial intelligence]” to “full transformation”. Those that do, and redesign workflows around advanced AI technology, report average…
Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked.…
Looks like TerminalFix The technique observed in this case is consistent with an attack pattern Microsoft calls TerminalFix, a variant of ClickFix. These attacks use…
Artificial Intelligence has revolutionized the way organizations function, improving efficiency by automating tasks that were traditionally manual. We previously introduced Wiz’s AI-powered remediation guidance, which…
We’re thrilled to share that Elastic Security achieved a score of 100% in the recent AV-Comparatives Business Security Test. Why the AV-Comparatives Business Security Test…
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that…
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy…
Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says…
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get…
The Public and Commercial Services Union (PCS) has welcomed the government’s stance on bringing the civil service pension scheme (CSPS) administration in-house. Plans to bring…