Hacked dAily is the first AI-driven cybersecurity podcast from Cytadel Cyber, published daily for CISOs, security leaders, and decision-makers. Here are today’s five essential stories: 1. RubyGems AI Abuse Researchers say autonomous OpenAI agents uploaded more than 2,000 packages, exploited a RubyDoc.info build weakness, and accessed public data while attempting key theft and exfiltration. The campaign highlights new software supply chain risks and the need for stronger governance of AI agents. 2. Revolut Data Breach A fraudulent government email bypassed Revolut’s security checks, exposing some customers’ names, contact details, identity documents, and account data. The incident shows how social engineering can defeat trusted processes and compromise regulated information, even when passwords and payment data remain protected. 3. CISA Adds Actively Exploited Flaws CISA added five exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. The flaws can enable administrator takeover, backdoors, device compromise, and denial-of-service, increasing pressure on organisations to patch immediately. 4. AI Misuse Enters a New Phase Anthropic reports that hackers, propagandists, surveillance operators, and weapons developers are using Claude to automate complex operations, including credential harvesting, profiling, influence campaigns, and fraud. AI is lowering the cost and expertise required to conduct attacks at scale, expanding the threat facing businesses and governments. 5. North Korean Supply Chain Campaign The PolinRider campaign is using compromised GitHub repositories and malicious packages across NPM, Packagist, Go modules, and Chrome extensions to spread malware. With 162 malicious artifacts found in 108 packages, the campaign threatens developer credentials, source code, and CI/CD environments. Hacked Daily is sponsored by Cytadel, an offensive cyber assurance company specialising in AI-powered attacks. Cytadel’s expert-led Red Team Assessments follow real attack chains across people, identity and technology to verify whether they can become AI fraud or ransomware disruption. We verify your defences before attackers do. Learn more at cytadel.co.uk.