For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
The “Rogue Agent” vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project.
The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations appeared first on SecurityWeek.
DuckDuckGo browser now blocks YouTube video ads
GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Everything a reviewer would check matches. The commit’s hash does not. That matters
The Verification Step Is the New ATO Battleground in 2026
That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in.
Passkeys are now mainstream.
Telco giant KDDI says data breach affects over 12 million people
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA’s Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch.
The post CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws appeared first on SecurityWeek.
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication.
The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek.
