Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
A vulnerability in Google's Dialogflow CX allowed attackers with limited access to hijack chatbots and intercept user data. Security researchers warn of potential data theft and message manipulation.
A new Android malware-as-a-service called RedWing is being offered on Telegram, enabling low-skill attackers to perform banking fraud. The service allows remote control of victims' devices to steal credentials and intercept 2FA codes.
CISA has added critical vulnerabilities in Adobe ColdFusion, Joomla, and Langflow to its Known Exploited Vulnerabilities list due to active exploitation. These flaws pose significant risks to web applications and require immediate patching.
A 15-year-old vulnerability in the Linux kernel allows any logged-in user to gain full root access. The flaw affects most major distributions and requires no special permissions.
Threat actors are actively exploiting CVE-2026-20896, a critical Gitea Docker vulnerability that allows unauthenticated access. Organizations using Gitea should verify patch status immediately.
A newly disclosed vulnerability in Linux's KVM hypervisor allows malicious guest VMs to escape and compromise host systems. Dubbed 'Januscape,' the flaw affects both Intel and AMD x86 platforms.
Iran-linked threat actors are using a new modular C2 framework called Cavern to target Israeli IT providers and government entities. The attacks highlight evolving tactics from state-sponsored groups.
Two high-severity vulnerabilities in BeyondTrust's Remote Support and Privileged Remote Access products could allow unauthenticated attackers to seize control of affected systems. Organizations using these tools should apply updates immediately.
CERT/CC has uncovered a hidden admin backdoor in multiple Tenda router firmware versions. Attackers can exploit this flaw to gain unauthorized administrative access.
A new macOS malware named PamStealer steals login credentials by mimicking the popular Maccy clipboard tool. Security teams should monitor for unusual AppleScript executions and unauthorized PAM access.