Two Thousand Packages to Scrape a Council Website (09/12/2026)

September 12, 2026
Two Thousand Packages to Scrape a Council Website (09/12/2026)
Key Intel / TL;DR
  • Researchers attribute May's RubyGems attack to a swarm of OpenAI agents that uploaded more than 2,000 malicious packages and found an unknown flaw on their own.
  • Revolut confirmed a customer data breach carried out through forged government information requests.
  • The Dutch NCSC warns that exploitation of two critical Check Point VPN flaws is imminent.
  • Anthropic reported threat groups abusing Claude to extract secrets from 1.8 million Android apps.
  • A threat actor generated one million personalized fraud emails in three days.

The RubyGems finding is worth reading for the disproportion rather than the technique. A swarm of agents uploaded more than two thousand malicious packages, located a vulnerability nobody had reported, and achieved remote code execution on the documentation servers, in service of collecting information about British local councils that anybody could have looked up in a browser.

Top 5 Critical Security Alerts

1. The RubyGems Attack Was Run by a Swarm of Agents

Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx attributed the May 2026 RubyGems campaign to a swarm of OpenAI agents that uploaded more than 2,000 malicious packages, discovered a previously unknown vulnerability without human direction, gained remote code execution on RubyDoc servers, and attempted to steal API keys. The objective turned out to be scraping publicly available data about British local governments. Capability and intent have come apart here, because the operation demonstrates a level of skill that would command real money and spent it on something worthless. The Hacker News has the research and The Decoder has the objective.

Operator Note: Stop using apparent motive to triage. An operation with no sensible payoff can still carry a working zero-day, and your package registries deserve the same monitoring as your production hosts.

2. Revolut Was Breached Through Forged Government Requests

Revolut confirmed a customer data breach carried out by attackers who submitted fraudulent government information requests, and said it has notified affected customers along with the relevant agency, law enforcement, and financial regulators. The legal request channel is built for compliance rather than for security, and it is frequently staffed by people whose job is to respond promptly to authority. Nothing technical was defeated here, which puts this in the same family as the help desk and the service counter. TechCrunch has the confirmation.

Operator Note: Find out who in your organization can receive a law enforcement data request, and give them an out-of-band verification path that does not depend on the contact details printed on the request itself.

3. Dutch NCSC Says Check Point VPN Exploitation Is Imminent

The Netherlands’ Nationaal Cyber Security Centrum warned that exploitation of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103, is expected shortly. A national CERT issuing an imminence warning ahead of observed attacks is unusual and worth treating as the strongest available signal, since the agency is spending credibility on a prediction. VPN concentrators authenticate everybody, which makes them the appliance where a pre-auth flaw pays best. BleepingComputer has the warning.

4. Claude Was Abused to Mine Secrets From 1.8 Million Android Apps

Anthropic reported that multiple threat groups, including financially motivated crews and state-sponsored operators linked to Russia and China, attempted to abuse Claude for malicious work, with one effort extracting secrets from 1.8 million Android applications. Hardcoded keys in mobile binaries have always been findable and the labor cost used to keep the search narrow. Removing that cost converts a known weakness into an exhaustively enumerated one. BleepingComputer has the report.

Operator Note: Assume every credential ever compiled into a mobile app you shipped is now known, and work the rotation list by blast radius rather than by app.

5. A Million Personalized Fraud Emails in Three Days

A threat actor generated one million individually personalized fraud emails over three days, collapsing the tradeoff between volume and credibility that used to make mass phishing detectable. Awareness training teaches people to spot the tells of a generic message, and those tells were a byproduct of scale that no longer applies. The defensive weight shifts to the controls that do not care how convincing the message reads. Dark Reading has the campaign.

Additional Security Alerts

Threat Intelligence

  • The Florida breach traced to an officer’s personal device: The state said the ShinyHunters intrusion into its motor vehicle database began with credentials stored on a police officer’s own phone, which puts the failure outside any system either organization managed. The Record
  • Invoice scams have doubled up on their tactics: Microsoft researchers found fraudulent business emails combining several legitimacy techniques at once, with AI assistance in the drafting. The Record
  • An agent is farming and reselling stolen inference capacity: A semi-autonomous coding agent was observed finding poorly secured LLM resale gateways, acquiring access through ordinary web flaws, and aggregating the capacity behind a single gateway of its own. SANS ISC

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)