Daily Recap, this cybersecurity update highlights ongoing exploitation and misuses across AI and cloud services, including conversation hijacking risks tied to Dialogflow, alongside federal patch pressure for Adobe ColdFusion, Langflow, and Joomla flaws in the KEV catalog. It also covers breach and fraud activity from KDDI’s 12M+ email exposure and Accenture’s confirmed incident, plus threats ranging from LONGLEASH malware to RedWing Android MaaS and device-code flow abuse via DEBULL.
#Dialogflow #RogueAgent #AdobeColdFusion #Langflow #Joomla #KEV #KDDI #Accenture #LONGLEASH #RedWing #Tenda #DEBULL
#Dialogflow #RogueAgent #AdobeColdFusion #Langflow #Joomla #KEV #KDDI #Accenture #LONGLEASH #RedWing #Tenda #DEBULL
AI & Cloud Threats
- AI tools and chatbots were shown to be vulnerable to conversation hijacking and service-desk abuse, while governments and researchers pushed new scanning and patching efforts to close the gap. – AI Attacks, Dialogflow Bug, Rogue Agent, AI Gap, Mythos Scan
Exploited Vulnerabilities
- CISA and researchers flagged active exploitation of Adobe ColdFusion, Langflow, and Joomla flaws, with federal agencies told to patch immediately and multiple advisories added to the KEV catalog. – Langflow Patch, Exploit Alert, KEV Update, ColdFusion Deadline, ColdFusion Exploited
- Critical flaws were also reported in Gitea and Ubiquiti UniFi OS, underscoring a broad wave of high-severity product issues under active review. – Gitea Flaw, UniFi OS Bug
- A 15-year-old GhostLock flaw was found to enable root access and container escape across most Linux distributions. – GhostLock Flaw
Data Breaches & Extortion
- Japanese telecom giant KDDI said a cyberattack exposed data from more than 12 million people, including email records. – KDDI Breach, Email Exposure
- Accenture confirmed a breach after stolen data was offered for sale, while a county government reportedly paid $1 million to a cyber extortion group. – Accenture Breach, County Payment
Nation-State & Hacktivism
- Spain arrested suspected hackers linked to Russian-aligned hacktivist campaigns, signaling continued law-enforcement pressure on pro-Kremlin activity. – Russian Hacktivist, Pro-Russian Arrest
- Chinese operators developed LONGLEASH malware to expand an ORB network, showing ongoing infrastructure-building by advanced threat actors. – LONGLEASH Malware
Malware & Mobile Fraud
- RedWing was marketed as a MaaS platform for Android bank fraud, rented out through Telegram to lower the barrier for cybercriminals. – RedWing MaaS
- A hidden backdoor in Tenda router firmware granted admin access, creating a persistent foothold for attackers. – Tenda Backdoor
Identity, Access & DevOps
- Microsoft account compromise risks rose as DEBULL abused the device-code flow to target M365 users and steal credentials. – DEBULL Abuse
- GitHub Actions security gaps let an attack pattern evade common CI scanners, highlighting supply-chain blind spots. – GitHub Actions
Policy & Consumer Security
- Britain outlined plans for an autonomous AI “Cyber Shield,” while a Texas age-verification app law was allowed to take effect by the Supreme Court. – Cyber Shield, Texas Law
- DuckDuckGo added YouTube ad blocking to its browser, expanding its built-in privacy and anti-tracking protections. – DuckDuckGo Ad Block