New macOS ClickFix attack silently mounts DMGs to push infostealer
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke
Dragos Unveils AI for OT Security
Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset.
The post Dragos Unveils AI for OT Security appeared first on SecurityWeek.
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Attackers could abuse Dify’s multi-tenant cloud service to read private chats, preview other tenants’ documents, and reach internal APIs.
The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.
Scattered Spider members plead guilty to hacking Transport for London
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user’s email address and did nothing else.
The point was to show
Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO 14409 leaves national security systems on a separate track.
The deadlines matter because of a threat that does not
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
Effective June 18, 2026, the latest version of “actions/checkout,” the official GitHub action for checking out a repository into the
