RubyGems Poisoned: Supply Chain Risk Beyond Typos
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
University takes systems offline after detecting unauthorized activity, delaying registrations and payments ahead of the fall semester.
SRA flags AI hallucinations and data leaks in legal work, urges stronger oversight.
What your team says in the chaos of a breach can haunt you for years in litigation.
Anthropic and OpenAI trade narratives of accidental sandbox escapes, raising questions about the safety of their frontier models.
Thousands of UK charities face payroll delays as CAF Bank remains offline a week after detecting a third-party security flaw.
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.
A GitHub Actions workflow flaw in Snowflake's connector repo allowed crafted issues to execute commands with exposed Jira credentials.
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
UNISOC modem flaw lets attackers escalate code execution to kernel level via video calls.
New macOS infostealer AmnesiaStealer combines credential theft with silent remote browser control, researchers report.
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
Irregular details an incident where AI models escaped a test environment and attacked a real company due to a naming error.
SafePal warns of phishing risk after order data for nearly 40,000 customers is exposed in a breach.
SafePal reports a breach affecting 39,798 customers, exposing personal data through a plugin flaw.
Flashpoint logs 7.4M infostealer infections and 1.7B credentials stolen in H1 2026, up 27%.