Click any tag below to further narrow down your results
Links
This daily digest covers a mass credential harvest via FortiBleed targeting FortiGate firewalls, new backdoors like ModeloRAT and Mistic tied to ransomware brokers, and critical data-exposure flaws in platforms such as Dify AI. It also highlights supply-chain risks in open-source CI/CD workflows, Anthropic’s Mythos model uncovering classified-system weaknesses, and industry moves on AI-driven SecOps and network-layer virtual patching.
- FortiBleed brute-forced 430,000+ FortiGate firewalls since February, harvesting over 110 million credentials across 24 protocols for resale
- Four critical Dify AI flaws (CVE-2026-41947 to -41950) let any console user read other tenants' chats, files, and internal APIs; patched in 1.14.2
- ModeloRAT and diskless Mistic backdoors tied to the Woodgnat access broker use signed pythonw.exe and DLL sideloading to evade detection
- Cordyceps research found 300 CI/CD exploit chains across 30,000 GitHub Actions workflows letting free-tier accounts steal tokens and taint builds at Microsoft, Google, Apache, and Cloudflare
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0’s new security features.
- Compromised Klue OAuth tokens let the Icarus extortion group siphon Salesforce data via ~1,000 API calls in 15-minute bursts over a full day
- Romanian phishers spoofed a Boots "free sample" campaign, hitting ~9 million customers via a hacked Bolivian government checkout page and a compromised UK mail server
- GlassWASM malware hides in trojanized Open VSX extensions (ExarGD.vsblack, noellee-doc/flint-debug), using a Solana wallet to fetch encrypted C2 addresses for second-stage payloads
- Homebrew 6.0 adds default Bubblewrap sandboxing on Linux, a tap-trust opt-in system, and an OSV-based `brew vulns` vulnerability scanner
This issue covers fresh attacks on AI agent infrastructure—over 7,000 Langflow servers hit via chained bugs in LangGraph and LangChain—and a new agentjacking risk where exposed Sentry keys let attackers hijack Claude-based workflows. It also details Apple’s Beats Studio Buds wiretap patch, Gizmodo’s ClickFix malware incident, and ongoing FortiBleed fallout, plus guidance on client-side bot detection, post-quantum crypto, and microVM limits.
- 7,000+ Langflow servers are being actively compromised by chaining three known bugs across LangGraph, Langflow, and LangChain-core, giving attackers code execution and API key theft.
- A new "agentjacking" technique abuses exposed Sentry DSNs to inject fake error events that trick AI coding agents (Claude Code, Cursor, Codex) into running malicious commands and leaking AWS/GitHub credentials, bypassing traditional security controls entirely.
- Apple's Beats Studio Buds firmware fix (CVE-2025-20701) patches an Airoha Bluetooth chip flaw that let nearby attackers eavesdrop through unpaired earbuds and crack pairing keys.
- Roughly 1,000 organizations have been confirmed breached via FortiBleed, with attackers exporting configs, cracking password hashes via rented GPUs, and planting persistent backdoors (new admin accounts, SSH/RDP rules, IPsec tunnels).
This roundup covers the Tata Electronics data breach exposing Apple and Tesla secrets, a critical FFmpeg RCE patch, and Meta’s halted keystroke-tracking AI program. It also reviews Linux AF_ALG privilege escalation mitigation, new prompt-injection tactics against LLMs, OpenClaw skill-market threats, and OpenAI’s Daybreak security tools alongside warnings of near-term AI-driven cyberattacks.
- Tata Electronics breach exposed 200,000+ internal files including Tesla and Apple product specs, potentially aiding rivals and triggering regulatory exposure
- Meta scrapped its Model Capability Initiative after discovering it had leaked employees' keystrokes, mouse movements, private chats, and performance reviews company-wide
- Role confusion prompt attacks spiked LLM jailbreak success rates from 0% to 61%, though simple "destyling" of input text cut that back to 10%
- Five Eyes agencies warn frontier AI capable of crippling cyberattacks will arrive within months, not years
This digest covers new exploits in AI and enterprise platforms, including a path traversal flaw in Langflow, a ServiceNow tenant data leak, and critical Ivanti Sentry root bugs. It also highlights Anthropic’s ATT&CK mapping of AI-driven threats and evolving deepfake tactics for bypassing facial recognition.
- Langflow's unauthenticated file upload endpoint is under active exploitation, enabling remote code execution—patch or lock down auth immediately.
- Ivanti Sentry 9.9/10.0 has critical unauthenticated root/admin-creation bugs via a Tomcat API—upgrade to 10.5.2/10.6.2/10.7.1 now.
- Anthropic's ATT&CK mapping of 832 banned accounts found top-tier threat actors chaining fully autonomous multi-step attacks (recon, SSRF, SSH key theft, lateral movement) with no human prompting.
- Deepfake fraud rings (North Korean IT workers, a $38.4M Vietnamese laundering gang, and others) are defeating liveness checks by combining masks, injected video, and real-time deepfakes.
Mozilla used Anthropic’s Mythos Preview model to scan Firefox 150’s unreleased source code and flagged 271 security vulnerabilities before release. That’s a big jump from the 22 bugs found by Anthropic’s earlier Opus 4.6 model on Firefox 148, cutting out months of manual auditing.
- Mozilla used Anthropic's Mythos Preview model to find 271 security vulnerabilities in unreleased Firefox 150 code before release.
- That's a 12x jump from the 22 bugs Anthropic's Opus 4.6 model found in Firefox 148 the prior month.
- Firefox CTO Bobby Holley says AI compressed work that used to take security experts months into a fraction of the time.
- The results counter skeptics who suspected Anthropic was overhyping Mythos by restricting early access to select industry partners.
The article discusses a recent supply chain attack involving the popular Axios package, highlighting how an attacker installed malware without altering the original code. It emphasizes the challenges posed by AI in both coding and attacking, as automated systems can easily introduce vulnerabilities faster than traditional security measures can respond.
- Attackers hijacked a maintainer account and slipped a self-deleting RAT into Axios (100M+ weekly downloads) via a malicious dependency, leaving no CVE for traditional scanners to catch.
- AI coding agents are 50% more likely than humans to pick known-vulnerable dependencies and often hallucinate package names that attackers exploit via "slopsquatting."
- Attacks have shifted from targeting single packages to automated, ecosystem-wide worms, like the TeamPCP campaign that spread through 66 npm packages in days.
- Socket detected the malicious Axios dependency in 6 minutes by analyzing code behavior, versus the industry-average 267 days for breach detection.
Vitalik Buterin highlights significant vulnerabilities in decentralized stablecoins, including their reliance on the U.S. dollar, the risks associated with oracle data, and the challenges of staking incentives. He emphasizes that these design flaws could undermine the stability of these assets over time, suggesting that future stablecoins may need to consider broader price indexes instead of being dollar-dependent.
- Most decentralized stablecoins are still pegged to the US dollar, leaving them exposed to political and economic shocks; Buterin suggests broader price indexes or purchasing power metrics as an alternative.
- Reliance on oracles for real-world price data creates a manipulation risk that could undermine the entire stablecoin system.
- Staking-based security introduces risk because slashing penalties can reduce the value of staked collateral backing the stablecoin.
- Fixed collateral levels fail during sharp market downturns, risking the loss of the peg, so dynamic collateral management or new staking designs are needed.