Click any tag below to further narrow down your results
Links
This daily digest covers a mass credential harvest via FortiBleed targeting FortiGate firewalls, new backdoors like ModeloRAT and Mistic tied to ransomware brokers, and critical data-exposure flaws in platforms such as Dify AI. It also highlights supply-chain risks in open-source CI/CD workflows, Anthropic’s Mythos model uncovering classified-system weaknesses, and industry moves on AI-driven SecOps and network-layer virtual patching.
- FortiBleed brute-forced 430,000+ FortiGate firewalls since February, harvesting over 110 million credentials across 24 protocols for resale
- Four critical Dify AI flaws (CVE-2026-41947 to -41950) let any console user read other tenants' chats, files, and internal APIs; patched in 1.14.2
- ModeloRAT and diskless Mistic backdoors tied to the Woodgnat access broker use signed pythonw.exe and DLL sideloading to evade detection
- Cordyceps research found 300 CI/CD exploit chains across 30,000 GitHub Actions workflows letting free-tier accounts steal tokens and taint builds at Microsoft, Google, Apache, and Cloudflare
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0’s new security features.
- Compromised Klue OAuth tokens let the Icarus extortion group siphon Salesforce data via ~1,000 API calls in 15-minute bursts over a full day
- Romanian phishers spoofed a Boots "free sample" campaign, hitting ~9 million customers via a hacked Bolivian government checkout page and a compromised UK mail server
- GlassWASM malware hides in trojanized Open VSX extensions (ExarGD.vsblack, noellee-doc/flint-debug), using a Solana wallet to fetch encrypted C2 addresses for second-stage payloads
- Homebrew 6.0 adds default Bubblewrap sandboxing on Linux, a tap-trust opt-in system, and an OSV-based `brew vulns` vulnerability scanner
This issue covers fresh attacks on AI agent infrastructure—over 7,000 Langflow servers hit via chained bugs in LangGraph and LangChain—and a new agentjacking risk where exposed Sentry keys let attackers hijack Claude-based workflows. It also details Apple’s Beats Studio Buds wiretap patch, Gizmodo’s ClickFix malware incident, and ongoing FortiBleed fallout, plus guidance on client-side bot detection, post-quantum crypto, and microVM limits.
- 7,000+ Langflow servers are being actively compromised by chaining three known bugs across LangGraph, Langflow, and LangChain-core, giving attackers code execution and API key theft.
- A new "agentjacking" technique abuses exposed Sentry DSNs to inject fake error events that trick AI coding agents (Claude Code, Cursor, Codex) into running malicious commands and leaking AWS/GitHub credentials, bypassing traditional security controls entirely.
- Apple's Beats Studio Buds firmware fix (CVE-2025-20701) patches an Airoha Bluetooth chip flaw that let nearby attackers eavesdrop through unpaired earbuds and crack pairing keys.
- Roughly 1,000 organizations have been confirmed breached via FortiBleed, with attackers exporting configs, cracking password hashes via rented GPUs, and planting persistent backdoors (new admin accounts, SSH/RDP rules, IPsec tunnels).
This roundup covers the Tata Electronics data breach exposing Apple and Tesla secrets, a critical FFmpeg RCE patch, and Meta’s halted keystroke-tracking AI program. It also reviews Linux AF_ALG privilege escalation mitigation, new prompt-injection tactics against LLMs, OpenClaw skill-market threats, and OpenAI’s Daybreak security tools alongside warnings of near-term AI-driven cyberattacks.
- Tata Electronics breach exposed 200,000+ internal files including Tesla and Apple product specs, potentially aiding rivals and triggering regulatory exposure
- Meta scrapped its Model Capability Initiative after discovering it had leaked employees' keystrokes, mouse movements, private chats, and performance reviews company-wide
- Role confusion prompt attacks spiked LLM jailbreak success rates from 0% to 61%, though simple "destyling" of input text cut that back to 10%
- Five Eyes agencies warn frontier AI capable of crippling cyberattacks will arrive within months, not years