1 link tagged with all of: supply-chain + infosec + ai-security + malware + vulnerabilities
Links
This daily digest covers a mass credential harvest via FortiBleed targeting FortiGate firewalls, new backdoors like ModeloRAT and Mistic tied to ransomware brokers, and critical data-exposure flaws in platforms such as Dify AI. It also highlights supply-chain risks in open-source CI/CD workflows, Anthropic’s Mythos model uncovering classified-system weaknesses, and industry moves on AI-driven SecOps and network-layer virtual patching.
- FortiBleed brute-forced 430,000+ FortiGate firewalls since February, harvesting over 110 million credentials across 24 protocols for resale
- Four critical Dify AI flaws (CVE-2026-41947 to -41950) let any console user read other tenants' chats, files, and internal APIs; patched in 1.14.2
- ModeloRAT and diskless Mistic backdoors tied to the Woodgnat access broker use signed pythonw.exe and DLL sideloading to evade detection
- Cordyceps research found 300 CI/CD exploit chains across 30,000 GitHub Actions workflows letting free-tier accounts steal tokens and taint builds at Microsoft, Google, Apache, and Cloudflare
infosec
vulnerabilities
malware
supply-chain
ai-security