Incident537 Downloads: Ruby Gem Hijack Timeline
What Happened An attacker compromised the maintainer account for the Ruby gem strong_password and published version 0.0.7 containing remote code execution capabilities. Rubygems.org reported 537 downl
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened An attacker compromised the maintainer account for the Ruby gem strong_password and published version 0.0.7 containing remote code execution capabilities. Rubygems.org reported 537 downl
IncidentWhat Happened A Denial of Service vulnerability (CVSS 5.3) in the Axios JavaScript HTTP client allowed attackers to force applications to process content beyond configured limits. This flaw affected a
GeneralYou re deploying AI agents at scale. Your compliance framework covers user access, service accounts, and third-party integrations. But what about the agents themselves? Enterprises expect to deploy an
IncidentA remote code execution vulnerability lay hidden in Webmin for over a year, affecting versions 1.890 through 1.920. This wasn t a coding mistake — it was a deliberate insertion by a malicious actor wh
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Mozilla s Zero Day Investigative Network (0DIN) demonstrated an attack exploiting AI coding agents through legitimate-looking GitHub repositories. The repository contained no malicious c
IncidentWhat Happened Spring Boot version 2.1.7 shipped with jackson-databind 2.9.9, a JSON parsing library containing two high-severity deserialization vulnerabilities (CVE-2019-14379 and CVE-2019-14439). Th
GeneralThe Conventional Wisdom The industry consensus suggests running AI-generated code in isolated sandboxes before it touches production. Tools like Greptile s TREX feature and Cursor s cloud agents creat
GeneralOver the past year, fewer companies are relying on AI systems for penetration testing. This isn t a failure of innovation—it s a market correction after inflated expectations met operational reality.
GeneralYour AI coding assistant just wrote 6,000 lines of code. It compiled. Tests passed. Your CI pipeline is green. But when a verification agent checked those same 6,000 lines against your team s actual r
IncidentWhat Happened Attackers are exploiting CVE-2026-12569 , a remote code execution vulnerability in PTC Windchill, to deploy web shells on vulnerable systems. The flaw has a CVSS score of 9.3. CISA added
IncidentWhat Happened SentinelLabs identified malware targeting MacOS systems that contains instructions designed to make LLM-assisted security products abort their analysis. The malware, detected under the r
IncidentWhat Happened On June 25, 2026, researchers identified a supply chain breach affecting the Leo Platform ecosystem on npm. Sonatype found 23 malicious package versions linked to the Shai-Hulud Miasma c
IncidentA supply chain attack targeting npm packages and GitHub Actions workflows revealed how attackers can now move across package ecosystems to harvest developer credentials at scale. The Miasma malware ca
IncidentIn January 2025, Polymarket users experienced a significant security breach when $3 million in cryptocurrency vanished from their wallets. The culprit? Malicious JavaScript injected through a third-pa
IncidentWhat Happened In August 2019, an attacker compromised a maintainer s RubyGems account for the rest-client library and inserted malicious code into versions 1.6.11 through 1.6.13. This backdoor allowed
ResearchYou re building AI-powered research tools. Your agents pull from Reddit, Stack Overflow, and community forums because that s where real-world knowledge lives. But here s what Cornell Tech just proved: