News

Dify DifyTap Flaws Expose Cross-Tenant AI App Data
Application Security
Dify DifyTap Flaws Expose Cross-Tenant AI App Data
Four critical Dify vulnerabilities named DifyTap allow cross-tenant access to private AI chats, uploaded files, and internal APIs. Patched in version 1.14.2.
Application Security
Fake AI Agent Skill Reaches 26,000 Agents in Supply Chain Test
Security firm AIR planted a fake AI agent skill that bypassed all scanners and reached 26,000 agents, exposing a supply chain flaw in AI skill ...
Cybersecurity
Canada’s CSIS Uses Court Warrant to Dismantle Foreign Botnet
CSIS used a court-authorized warrant to remove foreign botnet malware from Canadian servers and IoT devices in a first use of its threat reduction powers.
Cybersecurity
Elastic Exposes OXLOADER and CastleStealer in Russian Malvertising
Elastic Security Labs exposed OXLOADER and CastleStealer — two new Russian-linked malware families spread via fake Google Ads targeting software downloaders.
Application Security
FFmpeg PixelSmash Heap Overflow Enables RCE in Media Apps
JFrog disclosed CVE-2026-8461, a critical heap overflow in FFmpeg's video decoder enabling remote code execution when processing malicious video files.
Application Security
Microsoft AutoGen AI Framework Vulnerable to Localhost RCE
Microsoft disclosed AutoJack, a three-part vulnerability chain in AutoGen Studio that lets attackers hijack AI agents and execute arbitrary system commands.
Cybersecurity
WhatsApp Phishing Deploys ManageEngine RMM Malware Across Continents
Kaspersky found a WhatsApp phishing campaign using VBScript to install ManageEngine RMM software across multiple countries, granting attackers remote access.
Application Security
TeamPCP Open-Source Supply Chain Investigation Reveals Years of Access
Researchers investigated the TeamPCP threat group that exploited open-source speed culture for years of supply chain access across thousands of organizations.
Cybersecurity
Multiple Groups Exploit Critical FortiSandbox Flaws Across 200 Countries
Multiple sources confirm active exploitation of CVE-2026-25089 and CVE-2026-39813 against FortiSandbox, with credentials compiled for tens of thousands of appliances.
Cybersecurity
Kodak Confirms Data Breach After ShinyHunters Sets Leak Deadline
Kodak confirms a data breach after the ShinyHunters hackgroup claimed 2.2 million records exfiltrated, with the company asserting no threat to current operations.