‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows

GitHub’s Agentic Workflows Exposed by ‘GitLost’ Flaw A critical vulnerability in GitHub’s Agentic Workflows has been discovered, allowing attackers to leak private data from organizations’ code repositories without compromising accounts or exploiting software vulnerabilities. Dubbed “GitLost” by the researchers at Noma Security who found it, this flaw highlights a fundamental security challenge of agentic AI … Read more

Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft

A Critical Flaw in Google’s Dialogflow CX Exposed AI Chatbots to Data Theft Google has recently patched a critical vulnerability in its Dialogflow CX platform that would have allowed attackers to steal sensitive data from AI-powered chatbots and agents. The flaw, dubbed “Rogue Agent,” was discovered by Varonis researchers and reported to Google in November … Read more

Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Targets Marketing Pros with Google Credentials Heist** A sophisticated phishing campaign is duping marketing professionals into handing over their sensitive Google credentials by posing as job recruiters for top brands. The scammers are using legitimate platforms and techniques to evade detection, making it essential for victims to be vigilant. The campaign, … Read more

‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows

GitHub Agentic Workflows Left Vulnerable to Data Leaks via “GitLost” Flaw A critical flaw in GitHub’s Agentic Workflows has been discovered, allowing attackers to trick AI-powered automation into leaking sensitive data from private code repositories without compromising accounts or exploiting software vulnerabilities. Dubbed “GitLost,” the vulnerability was found by researchers at Noma Security and can … Read more

Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft

Google’s Dialogflow CX platform has been patched to fix a critical vulnerability that would have allowed attackers to steal sensitive data from AI-powered chatbots and agents. The “Rogue Agent” flaw, discovered by Varonis researchers in November 2025, was a permission boundary issue that could have enabled large-scale phishing campaigns and data theft. The vulnerability affected … Read more

Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Tricks Marketing Pros into Handing Over Google Credentials** A sophisticated phishing campaign is targeting marketing professionals’ Google accounts by posing as major corporate brands, such as Coca-Cola and Netflix, in an attempt to steal sensitive credentials. The campaign uses a range of tactics, including nested redirects and browser-in-the-browser attacks, to evade … Read more

Webinar tomorrow: Why modern email attacks require a new approach to defense

Email attacks continue to plague organizations worldwide, with phishing, business email compromise (BEC), and account takeover (ATO) remaining among the most persistent threats facing security teams. Despite investments in secure email gateways, multi-factor authentication, and identity protection, these types of attacks persist due to their sophisticated nature. Attackers have shifted their tactics from relying on … Read more