appsec.fyi · Sources

bankinfosecurity.com

10 curated AppSec resources from bankinfosecurity.com across 4 topics on appsec.fyi.

bankinfosecurity.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-08-21.

Date Added Resource Excerpt
2026-08-21 2026Rising Number of Cyberattacks Have AI-Assisted FingerprintsAILibrary detailing AI-assisted cyberattacks, specifically highlighting the use of Claude Code and OpenAI's GPT-4.1 API by threat actors. It enumerates techniques like semi-autonomous network intrusions, data exfiltration, and ransomware deployment. The library also points to vulnerabilities exploited, such as misconfigurations in FortiGate devices and authentication flaws, and mentions observed attacks against government agencies and financial firms in regions including Asia, Australia, and Europe.
2026-08-12 2026How Postman Embeds Wiz Risk Data Into Dev WorkflowsAPI SecLibrary integration embeds Wiz risk data into Postman's API Catalog, surfacing known exploitable vulnerabilities, secrets, and misconfigurations within developers' existing workflows. This approach provides one-click remediation commands directly in the interface, improving security KPIs by enabling developers to address risks quickly and efficiently, representing genuine "shift-left" security.
2026-08-12 2026Zoom Flaws Facilitate Zero-Click Remote Code ExecutionRCEWriteup of "Zoomsday" vulnerabilities (CVE-2026-53415, CVE-2026-53413, CVE-2026-53414) in Zoom's annotation feature, enabling zero-click remote code execution. Exploits targeting memory corruption flaws allow attackers to take complete control of a victim's device during calls, steal data, or spy. While Zoom has patched these issues, users must update their clients, as server-side mitigations are ineffective with end-to-end encryption enabled. Reducing attack surface through meeting access controls and validating endpoint controls are recommended defenses.
2026-07-14 2026The AI Supply Chain Is Your Latest Unguarded Attack SurfaceSupply ChainLibrary for securing AI supply chains, addressing risks across four layers: third-party model APIs, open-source repositories (mentioning pickle file serialization, typosquatting, and malicious LoRA adapters), orchestration frameworks (highlighting prompt injection and RAG poisoning), and infrastructure (including GPU, hyperscaler, and physical hardware concerns). Controls involve vendor assessment, internal model registries, zero trust principles for orchestration, and geographic distribution for infrastructure.
2026-05-27 2026Glassworm Group: Software Supply-Chain Attackers DisruptedSupply ChainAnalysis of the Glassworm Group's software supply-chain attacks details their use of GlasswormRAT, a Node.js-based remote access Trojan, to poison code repositories like VS Code Marketplace and Open VSX. The group leverages stolen developer credentials to force-push malicious code into default branches of over 300 GitHub repositories, targeting Windows, Mac, and Linux systems. Their resilient command-and-control infrastructure utilized the Solana blockchain, BitTorrent, and Google Calendar for C2 server resolution. Indicators of compromise include connections to CrowdStrike-operated IP address 164.92.88.210.
2026-05-26 2026Socket Raises $60M for Wider Software Supply-Chain DefenseSupply ChainLibrary for securing software supply chains, Socket provides protection for developer endpoints, AI ecosystems, browser extensions, and editor plug-ins. It addresses the growing threat of malicious packages and dependencies introduced by AI development tools and open-source packages, offering features like Socket Firewall to block threats before they reach pipelines. The company has secured $60 million in funding to expand its security controls across broader software ecosystems and enhance its human-vetted threat analysis capabilities.
2026-05-13 2026Mass Supply-Chain Attack Slams npm and PyPi Hits Mistral AISupply ChainLibrary for securing supply chains against the "Mini Shai-Hulud" worm, which has targeted npm and PyPI packages, including those from Mistral AI. This worm autonomously spreads by stealing credentials from over 100 locations, including cloud platforms and developer tools, and can include a wiper payload. Recommendations include implementing code cooldown periods before integrating new packages, enforcing multifactor authentication, and routine key rotation to mitigate these attacks.
2026-04-24 2026Flurry of Supply-Chain Software Library AttacksSupply ChainLibrary security overview detailing recent supply-chain attacks targeting open-source repositories like npm and PyPI. Attackers compromise popular packages, such as LiteLLM, Axios, Xinference, Namastex.ai, Checkmarx KICS, and Bitwarden CLI, injecting malware to steal developer credentials, secrets, and tokens. These poisoned packages, distributed via automated CI pipelines, can spread rapidly through software dependencies, highlighting the fragility of current development practices.
2026-04-24 2026Cloudsmith Raises $72M for Software Supply-Chain SecuritySupply ChainLibrary providing software supply-chain security through artifact management. Cloudsmith, a platform from Twilio's former chief customer officer, raised $72 million to enforce policies, audit usage, and reduce exposure to malicious or compromised packages by acting as an intermediary between developers and public repositories. This approach transforms artifact management into a security layer, offering insights into package popularity, maturity, and known risks to both human developers and AI agents, while also integrating data from external security tools for more nuanced policy decisions.
2026-04-03 2026Under Fire: Attackers Target Flaws in F5 and Citrix GearRCELibrary: Actively exploited vulnerabilities in F5 BIG-IP APM (CVE-2025-53521, a critical remote code execution flaw) and NetScaler ADC/Gateway (CVE-2026-3055, a critical memory overread, and CVE-2026-4368, a session mix-up) are detailed. Attackers, including nation-state actors, are targeting these application delivery and security platforms, with F5 revising its BIG-IP APM flaw severity from denial-of-service to remote code execution, and CISA mandating patching for federal agencies. Memory leak vulnerabilities in Citrix products, like the previously disclosed CitrixBleed, continue to be a significant concern.