BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmty7mm7h1e7qhpu2w4d62eiw

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Also reported by 1 other source
Cyber Security News·7 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxw4ipv112thpu2as4mh8eu

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal […] The post CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks appeared…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxv1xvv0zvhhpu2xcq55b66

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest developers’ API keys through a then-undisclosed caching flaw. The episode, initially tracked as the GemStuffer campaign, demonstrates how autonomous agents can turn […] The post OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE appeared first on…

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxqax4w0usxhpu28hzr44xg

Users in Houthi-held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

Twilio status·Outage
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7hgeu4000qhmu2e4eut0l9

Voice Call Failures from a Subset of Twilio Phone Numbers to Hong Kong

Minor impact · Identified — Twilio customers may be experiencing voice call failures from a subset of Twilio Phone Numbers to network subscribers in Hong Kong. Our team has identified the cause, and is working to resolve the issue. We will provide another update in 24 hours or as soon as more information becomes available.

Data Breach Today·Confirmed Breach2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxi1urv0llshpu2721zismn

ID Verification Firm IDScan.net Confirms Data Breach

IDScan.net Confirms Breach - But Leaves Victim Count and Point of Entry Unanswered A Louisiana identity verification company has confirmed a breach reportedly tied to the darkweb sale of more than 153 million U.S. and Canadian driver's licenses, but its notice does not say how many people were affected or how attackers got in.

Also reported by 1 other source
Data Breach Today·5 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxi1urv0llrhpu27wv6jelr

Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison

Lytvynenko Admitted Developing Malware and Stealing Data for Conti A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for Conti, the ransomware operation blamed for more than 1,000 victims and $150 million in payments.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxi1urv0llqhpu2zbevboaj

Anthropic Says AI Is Lowering the Bar for Sophisticated Attacks

Threat Report Finds Multi-Agent Tools Let Less-Skilled Actors Scale Complex Operations Anthropic's Threat Intelligence team identified a series of attempted attacks using its AI systems by malicious actors. The report focuses not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxi1urv0llphpu2rjmrhx8m

Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform

Nir Zuk's Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hardware, storage, security software and local AI for regulated organizations that can't send sensitive data to external clouds.

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxhozra0l51hpu29ori1e7l

Why AI raises the stakes for exposure validation

AI dominated the conversation at Fal.Con 2026, but one of the most important takeaways wasn’t simply how AI is changing cyber defense. It was how AI is changing the speed and scale of a problem defenders already face. Security teams already have more vulnerabilities and security signals than they can reasonably act on. As AI makes it faster to discover vulnerabilities and determine whether they can be exploited, finding more weaknesses only makes one question more important: Which exposures…

CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxh1tow0kexhpu2ebfw9ljm

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.

Also reported by 1 other source
Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002ehku2mmo4teuw

The Department of Know: Liquid drained, CISA urges change, agentic whistleblowers

Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Alexandra Landegger, global head of cyber strategy & transformation, RTX, Mark Eggleston, CISO-at-large. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Big thanks to our sponsor, ThreatLocker This week, we looked at how AI is making attacks faster,…

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxdrjk30gpthpu29slsxyd2

ISMG Editors: Can Humans Still Keep AI Agents in Check?

Also: AI Agents Breathe New Life in Zero Trust, OpenAI's Chip Puts Nvidia on Notice In this week's panel, four ISMG editors discussed the growing challenge of keeping human beings in control of AI agents, what security leaders are saying about AI and cloud risk, and whether OpenAI's new chip could pose a serious challenge to Nvidia.

Also reported by 1 other source