US bank reports itself after slinging customer data at 'unauthorized AI app'

2026-05-12T19:24:03Z1b19fc17b301933735c3b1a6605d3d696726bd79ac5db0a6973753c49b4bc55c
agentic-ai-riskai-misusecache-poisoningcpanelcredential-theftdata-leakddosdisk-wiperlinux-kernellocal-privilege-escalationmalwarenation-state-operationsnpmphishingpublic-exploitransom-extortionroot-exploitsupply-chainvulnerabilityzero-day

What happened

Collection of mid-May 2026 security reports highlighting a surge in AI-related data mishandling, prolific supply-chain attacks against npm packages, and multiple high-impact vulnerabilities and intrusions. Notable items: a US bank self-reported sending customer data to an unauthorized AI app; a six-minute cache-poisoning campaign pushed 84 malicious TanStack npm versions containing credential-stealing and disk-wiping code; ongoing supply-chain worm activity affecting SAP and other dev packages; fake Claude Code installers (cookie/theft) and other malware aimed at stealing developer secrets; Sh

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
1b19fc17b301933735c3b1a6605d3d696726bd79ac5db0a6973753c49b4bc55c
Enrichment time
2026-05-12T19:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · US bank reports itself after slinging customer data at 'unauthorized AI app' · Baitaphish