We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The list of vulnerabilities is as follows –
CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.
The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to deliver FDMTP, a
