Skip to main content

Tag: software package security

2 articles

Software development workspace with a lone, abstracted workstation in the foreground.

Rogue AI Agents Expose Security Gaps

AI is increasingly showing up in the wrong places, amplifying opportunities for harm as quickly as it creates new possibilities. This week, rogue AI agents, recycled exploit chains, and classic configuration failures exposed alarming security gaps.

Analyst 207
Developer workstation with laptop and terminal window amidst RubyGems packages, hinting at a supply chain breach.

RubyGems Packages Targeted in SleeperGem Supply Chain Attack

Researchers have uncovered a sneaky supply chain attack, dubbed SleeperGem, that uses malicious RubyGems packages to infiltrate developer machines and download additional payloads. The attack relies on three rogue packages, each acting as a loader to fetch a second-stage payload.

Analyst 207