
A reported AI-agent campaign hit RubyGems with malicious packages, public-data scraping, and attempted API key theft.
The FBI says cybercriminals are targeting adults and minors by breaking into social media accounts to steal intimate images and videos for extortion campaigns.

The FBI is warning that cybercriminals are hacking into social media accounts belonging to adults and children to steal intimate explicit images and videos. According to the alert described by TechCrunch, victims are often extorted or see stolen content published online. The warning highlights a privacy and safety threat that can continue after the initial account compromise.
The FBI advisory says attackers use brute-force attempts with leaked or previously used passwords, phishing emails and fake domains that resemble legitimate social media login pages. Some also impersonate customer service representatives, claiming to work for Instagram or other social media companies, or contacting targets under the pretext of account recovery. The common thread is social engineering: getting victims to trust a message, link or login prompt that is not legitimate.
The FBI wrote that victims can face re-victimization through harassment, sextortion, stalking and other targeted attacks, including stolen content being advertised on a victim’s own social media page. Rachel Tobac, CEO of SocialProof Security, told TechCrunch that the FBI’s public alert could indicate these incidents are rising. She also said the attacks especially target young boys and described the issue as a major public health concern because some victims are driven to self-harm.
The article says users should rely on unique passwords stored in a password manager and turn on multi-factor authentication. Be skeptical of anyone who reaches out unprompted claiming to work for a social media company, since tech companies generally do not contact customers that way. The FBI also urges people to avoid storing intimate pictures in online accounts.

A reported AI-agent campaign hit RubyGems with malicious packages, public-data scraping, and attempted API key theft.

Anthropic says Claude was used in cyber, weapons, surveillance and model-distillation cases.

A Brevo breach let attackers send phishing emails to Trezor customers.
Nvidia’s CEO sees cybersecurity as AI’s next major business use case.