A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.
The breach targeted users of a popular AI package, compromising the software at its source. Attackers gained access to the package repository, allowing them to distribute malicious code to downstream users.
The leaked credentials included authentication tokens, API keys, and login information. The scale of the breach—terabytes of data from 2,500 users—suggests broad access to user accounts and systems.
Supply-chain attacks like this exploit trust in software dependencies. Users typically assume packages from official repositories are safe, making these attacks particularly effective.
Affected organizations should rotate all credentials associated with the compromised package. Security teams should audit systems for unauthorized access using exposed credentials. Developers should review dependencies for similar vulnerabilities and implement stricter package verification processes.
The incident underscores ongoing risks in software development pipelines and highlights the need for enhanced security controls across the AI ecosystem.
A data theft campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow customer portals to harvest sensitive information. The attackers use custom tools to access data exposed to anonymous users.
A new Android malware combo pairs NFC relay malware called WindRelay with the SpyNote remote administration tool to steal credit card data and conduct fraud in real time.
Unknown actors are conducting widespread vulnerability scans while impersonating AI assistants like ClaudeBot, according to reports circulating in security communities.
A critical vulnerability in Adobe Commerce and Magento platforms is being actively exploited to compromise customer accounts. The flaw, tracked as CVE-2026-71362, poses immediate risk to e-commerce operations worldwide.