Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Threat actor 'Lurking Lizard' has been running a malicious proxy service using fake software installers since 2022. Over 230 domains were used to distribute malware disguised as legitimate applications.
Six popular AI coding tools are vulnerable to symlink-based attacks that can lead to remote code execution. These flaws allow malicious repositories to gain unauthorized access to developers' systems.
Security researchers demonstrate how AI agents designed to detect vulnerabilities can be manipulated into running malicious code. The 'Friendly Fire' attack targets autonomous AI systems like Claude Code and Codex.
Meta's new Muse Image AI tool allows users to generate content using public Instagram photos without explicit consent. The feature is enabled by default, sparking privacy and security discussions.
A new phishing campaign leverages Microsoft's legitimate device-code authentication flow to bypass traditional detection methods. The attack uses collaboration-themed lures to trick users into granting access to their Microsoft 365 accounts.
A vulnerability in Google's Dialogflow CX allowed attackers with limited access to hijack chatbots and intercept user data. Security researchers warn of potential data theft and message manipulation.
A new Android malware-as-a-service called RedWing is being offered on Telegram, enabling low-skill attackers to perform banking fraud. The service allows remote control of victims' devices to steal credentials and intercept 2FA codes.
CISA has added critical vulnerabilities in Adobe ColdFusion, Joomla, and Langflow to its Known Exploited Vulnerabilities list due to active exploitation. These flaws pose significant risks to web applications and require immediate patching.
A 15-year-old vulnerability in the Linux kernel allows any logged-in user to gain full root access. The flaw affects most major distributions and requires no special permissions.
Threat actors are actively exploiting CVE-2026-20896, a critical Gitea Docker vulnerability that allows unauthenticated access. Organizations using Gitea should verify patch status immediately.