‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows

GitHub Agentic Workflows Left Vulnerable to Data Leaks via “GitLost” Flaw A critical flaw in GitHub’s Agentic Workflows has been discovered, allowing attackers to trick AI-powered automation into leaking sensitive data from private code repositories without compromising accounts or exploiting software vulnerabilities. Dubbed “GitLost,” the vulnerability was found by researchers at Noma Security and can … Read more

Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft

Google’s Dialogflow CX platform has been patched to fix a critical vulnerability that would have allowed attackers to steal sensitive data from AI-powered chatbots and agents. The “Rogue Agent” flaw, discovered by Varonis researchers in November 2025, was a permission boundary issue that could have enabled large-scale phishing campaigns and data theft. The vulnerability affected … Read more

Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Tricks Marketing Pros into Handing Over Google Credentials** A sophisticated phishing campaign is targeting marketing professionals’ Google accounts by posing as major corporate brands, such as Coca-Cola and Netflix, in an attempt to steal sensitive credentials. The campaign uses a range of tactics, including nested redirects and browser-in-the-browser attacks, to evade … Read more

Webinar tomorrow: Why modern email attacks require a new approach to defense

Email attacks continue to plague organizations worldwide, with phishing, business email compromise (BEC), and account takeover (ATO) remaining among the most persistent threats facing security teams. Despite investments in secure email gateways, multi-factor authentication, and identity protection, these types of attacks persist due to their sophisticated nature. Attackers have shifted their tactics from relying on … Read more

Accenture confirms breach after hacker offers stolen data for sale

Accenture’s 35GB Data Heist Exposed, Company Remediates Breach with Minimal Impact A brazen cyberattack on IT services giant Accenture has left the company scrambling to contain the fallout. Threat actor “888” claims to have stolen a staggering 35 GB of sensitive data, including source code and personal access tokens, from Accenture’s systems in July. The … Read more

Microsoft to enable Windows settings backup by default for orgs

Microsoft has announced a significant change in its approach to data protection and device management, with far-reaching implications for enterprise users. As of the latest update to Windows 11, version 26H2, Microsoft will enable by default the backup and restore tool for organizations, previously known as “Windows Backup for Organizations,” on eligible devices. This tool … Read more

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A Critical Linux Flaw Allows Attackers to Escape Virtual Machines and Take Control of Hosts A recently patched vulnerability in the Linux kernel has been discovered to allow attackers to escape virtual machines (VMs) and execute arbitrary code on the host, potentially leading to a complete takeover. Dubbed “Januscape,” this flaw affects both Intel and … Read more

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese Hackers Expand Sophisticated ORB Network with New Malware Capabilities A highly advanced Chinese hacking group, tracked as “UAT-7810,” has been quietly expanding its Operational Relay Box (ORB) network by compromising internet-facing networking devices. The hackers are using a new malware called LONGLEASH to gain access and control over these devices, which serve as secure … Read more

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Google Dialogflow CX, a popular platform for building conversational interfaces, was recently found to have a critical vulnerability that could have allowed attackers to hijack chatbots and steal sensitive user data. The flaw, discovered by AI-powered security researchers, highlights the growing importance of artificial intelligence in identifying and mitigating software vulnerabilities. The rogue agent flaw, … Read more