US bank reports itself after slinging customer data at 'unauthorized AI app'
2026-05-12T19:24:03Z•1b19fc17b301933735c3b1a6605d3d696726bd79ac5db0a6973753c49b4bc55c
agentic-ai-riskai-misusecache-poisoningcpanelcredential-theftdata-leakddosdisk-wiperlinux-kernellocal-privilege-escalationmalwarenation-state-operationsnpmphishingpublic-exploitransom-extortionroot-exploitsupply-chainvulnerabilityzero-day
What happened
Collection of mid-May 2026 security reports highlighting a surge in AI-related data mishandling, prolific supply-chain attacks against npm packages, and multiple high-impact vulnerabilities and intrusions. Notable items: a US bank self-reported sending customer data to an unauthorized AI app; a six-minute cache-poisoning campaign pushed 84 malicious TanStack npm versions containing credential-stealing and disk-wiping code; ongoing supply-chain worm activity affecting SAP and other dev packages; fake Claude Code installers (cookie/theft) and other malware aimed at stealing developer secrets; Sh
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 1b19fc17b301933735c3b1a6605d3d696726bd79ac5db0a6973753c49b4bc55c
- Enrichment time
- 2026-05-12T19:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.